*** This version of Confluence is for testing only and contains a copy of content from June 29th 2026. No changes will be preserved. ***
...
- An IAM policy (deny-marketplace-changes-policy) that prevents making changes to the AWS Marketplace, including purchasing subscriptions
- An IAM role (shib-limitedadmin_no_adminmarket) that combines the deny-marketplace-changes-policy policy with the built-in AdministratorAccess policy to create a role that has broad privileges in AWS, but does not allow Marketplace changes.
...
- In the target AWS account, create a new CloudFormation stack using the template.yaml file.
- Create an Active Directory group that contains the people you wish to have access to the shib-limited_admin role admin_no_market role in your AWS account.
- Make a request to cloud-support@cornell.edu asking that the shib-limitedadmin_no_adminmarket role be configured for use by your AWS account. Optionally, request that a similar AWS SSO role be created as well. Be sure to provide the name of the AD group you created above.
- Once the Cloud Team confirms that the shib-limited_admin group admin_no_market group and/or the AWS SSO role is enabled, ask your team to begin using the new role(s) when using your AWS account.
...