SlideShare una empresa de Scribd logo
1 de 44
Descargar para leer sin conexión
AWS Identity and
Access Management
Jim Scharf
7/11/2013
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Jim Scharf
Director, AWS Identity and Access Management
Joined AWS in 2004
Own
•  AWS Identity and Access Management
•  Authentication, Authorization
•  Federation
Introductions
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Enable businesses and developers
to use web services*
to build scalable, sophisticated applications.
*What people now call “the cloud”
AWS Mission
Free steak
campaign
Facebook
page
Mars exploration
operations
Consumer social app
Gene sequencing Marketing web site Interactive TV apps Financial markets
analytics
Web site &
media sharing
Disaster recovery Media streaming Web and mobile apps
Diverse	
  Customers,	
  Wide	
  Range	
  of	
  Use	
  Cases	
  
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Mission-­‐criFcal	
  
Projects	
  	
  
Mars	
  Rover	
  Image	
  
processing	
  
Video	
  Streaming	
  
for	
  Landing	
  
Scale	
  up	
  as	
  
needed	
  
Highly	
  Parallel	
  
Processing	
  
Whole	
  World	
  
Watching	
  
One-­‐Time	
  Event	
  
Mars	
  Rovers	
  OperaFons
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Panoramas	
  of	
  5	
  Gigapixels,	
  created	
  on	
  AWS	
  in	
  just	
  5	
  minutes!	
  
Curiosity
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Daily	
  Mars	
  Rover	
  Data	
  Processing	
  Window	
  (2	
  hours)	
  
Serial	
  Process	
   Upload	
  Plan	
  
Pre-­‐cloud:	
  
Parallel	
  
Process	
  
Upload	
  Plan	
  
Cloud:	
  
Increased	
  available	
  mission	
  planning	
  Fme	
  by	
  1.5	
  hours!	
  
Mission	
  Data	
  Processing
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
More on NASA & AWS
AWS	
  Re:Invent	
  Conference,	
  2012	
  Keynote	
  Video	
  
hp://youtu.be/8FJ5DBLSFe4?t=11m58s	
  	
  
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Compute	
   Networking	
   Storage	
  &	
  	
  CDN	
  
Amazon	
  EC2	
  
Amazon	
  ElasFc	
  MapReduce	
  
Amazon	
  ElasFc	
  Load	
  Balancer	
  
	
  
Amazon	
  Route	
  53	
  
Amazon	
  Virtual	
  Private	
  Cloud	
  
AWS	
  Direct	
  Connect	
  
	
  
Amazon	
  S3	
  
Amazon	
  Glacier	
  
Amazon	
  EBS	
  
AWS	
  Import/Export	
  
Amazon	
  CloudFront	
  
	
  
Database	
   App	
  Services	
   Management	
  
Amazon	
  RDS	
  
Amazon	
  DynamoDB	
  
Amazon	
  ElasFCache	
  
Amazon	
  Redshie	
  
	
  
Amazon	
  CloudSearch	
  
Amazon	
  SWF	
  
Amazon	
  SQS	
  (Queues)	
  
Amazon	
  SNS	
  (NoFficaFons)	
  
Amazon	
  SES	
  (Email)	
  
Amazon	
  ElasFc	
  Transcoder	
  
	
  
AWS	
  IAM	
  
Amazon	
  CloudWatch	
  
AWS	
  ElasFc	
  Beanstalk	
  
AWS	
  CloudFormaFon	
  
AWS	
  Data	
  Pipeline	
  
AWS	
  OpsWorks	
  
AWS	
  CloudHSM	
  
AWS	
  Trusted	
  Advisor	
  
AWS	
  Marketplace	
  
AWS Services
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Access control
for AWS services and resources
AWS Identity and Access Management
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Difference #1
Image	
  courtesy	
  of:	
  	
  hp://imgsrc.hubblesite.org/hu/db/images/hs-­‐2005-­‐01-­‐a-­‐full_jpg.jpg	
  
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
AWS Scale
•  $5.2B e-commerce company
•  7,800 employees
•  A whole lot of servers!
Every day (on average), AWS
adds server capacity equivalent
to that entire $5.2B enterprise
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Trillions
Resources
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Million+
Requests/Second	
  
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Hundreds of
Thousands
Customers
in 190 countries
each with one to millions of identities
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Lots!
Servers	
  
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Global
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Difference #2
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Resources
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Cloud Services
Amazon	
  
EC2	
  
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Instance O/S
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Cloud Services
Amazon	
  
EC2	
  
Amazon	
  
S3	
  
Amazon	
  
ElasFc	
  
MapReduce	
  
AWS	
  
Storage	
  
Gateway	
  
Amazon	
  
DynamoDB	
  
Amazon	
  
RDS	
  
Amazon	
  
ElasFCache	
  
Amazon	
  
Route	
  53	
  
Amazon	
  
VPC	
  
Amazon	
  
CloudFront	
  
Amazon	
  
CloudWatch	
  
Amazon	
  
ElasFc	
  
Beanstalk	
  
AWS	
  
CloudFormaFon	
  
AWS	
  IAM	
  
Amazon	
  
SQS	
  
Amazon	
  
SES	
  
Amazon	
  
SNS	
  
Amazon	
  
CloudSearch	
  
Amazon	
  
SWF	
  
Amazon Redshift
OpsWorks	
  
Amazon	
  ElasFc	
  
Transcoder	
  
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Cloud Resources
Amazon	
  
EC2	
  
Amazon	
  
S3	
  
Amazon	
  
ElasFc	
  
MapReduce	
  
AWS	
  
Storage	
  
Gateway	
  
Amazon	
  
DynamoDB	
  
Amazon	
  
RDS	
  
Amazon	
  
ElasFCache	
  
Amazon	
  
Route	
  53	
  
Amazon	
  
VPC	
  
Amazon	
  
CloudFront	
  
Amazon	
  
CloudWatch	
  
Amazon	
  
ElasFc	
  
Beanstalk	
  
AWS	
  
CloudFormaFon	
  
AWS	
  IAM	
  
Amazon	
  
SQS	
  
Amazon	
  
SES	
  
Amazon	
  
SNS	
  
Amazon	
  
CloudSearch	
  
Amazon	
  
SWF	
  
Amazon Redshift
OpsWorks	
  
Amazon	
  ElasFc	
  
Transcoder	
  
Instances	
   Files	
  
AMIs	
  
Spot	
  Instances	
  
Volumes	
  
Messages	
  
Snapshots	
  
Security	
  Groups	
  
ElasFc	
  IPs	
   Placement	
  Groups	
  
Users	
  
Groups	
  
Roles	
  
Load	
  Balancers	
  
Autoscaling	
  Groups	
  
Network	
  Interfaces	
  
Queues	
  
Topics	
  
Domains	
  
Workflows	
  
ApplicaFons	
  
Templates	
  
DistribuFons	
  
Buckets	
  
Stacks	
  
Apps	
  
Layers	
   Clusters	
  
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
AWS Marketplace
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Difference #3
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Customers
•  Individual Developers
•  Students
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Hear about AWS
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Create Account
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Innovate!
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Customers
•  Individual Developers
•  Students
•  Startups
•  SMBs
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
IAM
•  Users, Groups, Permissions
–  Individual security credentials
–  Secure by default
–  Grant least privilege
•  Easy to use
–  Graphical user interface
–  Ability to script/automate (CLI & API)
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Customers
•  Individual Developers
•  Students
•  Startups
•  SMBs
•  Enterprises
•  Government
Agencies
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Control
•  AWS Multi-Factor Authentication
–  Hardware tokens
–  Smartphone app tokens
•  Credential management policies
•  Control billing, support, and AWS Marketplace
purchases
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
•  HIPAA
•  SOC 1/SSAE 16/ISAE
3402 (formerly SAS70)
•  SOC 2
•  SOC 3
•  PCI DSS Level 1
•  ISO 27001
•  FedRAMP
•  DIACAP and FISMA
•  ITAR
•  FIPS 140-2
•  CSA
•  MPAA
Compliance
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Federation
•  AWS Websites and/or APIs as relying party
•  Pre-packaged sample: Windows Active Directory as identity provider
SSO	
  
AcFve	
  Directory	
  
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Federation
•  Partners are critical
http://www.xceedium.com/xsuite/xsuite-for-amazon-web-services
http://www.okta.com/aws/
http://www.symplified.com/solutions/single-sign-on-sso
https://www.pingidentity.com/products/pingfederate/
•  More federation support coming…
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Customers
•  Individual Developers
•  Students
•  Startups
•  SMBs
•  Enterprises
•  Government
Agencies
•  Mobile Developers
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Web Identity Federation
•  App sign-in using 3rd party identity providers
– 
–  Facebook
–  Google (using OpenID Connect)
•  No server-side code required
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Web Identity Federation
US-EAST-1
AWS Services
STS	
  
Access	
  AWS	
  Resources	
  
IdenFty	
  
Provider	
   Assume	
  Role	
  
Amazon	
  S3	
   Amazon	
  
DynamoDB	
  
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
Customer Evolution
Username	
  &	
  
Password	
  
IAM	
  
Management	
  UI,	
  CLI,	
  API	
  
MulF-­‐Factor	
  AuthenFcaFon	
  
FederaFon	
  &	
  SSO	
  	
  
Password	
  Strength	
  Policy	
  
AWS	
  Marketplace	
  Control	
  
Enterprise	
  
Joe	
  
Startup/	
  
SMB	
  
No	
  addiGonal	
  charge	
  
Mobile	
  
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
•  Scale
•  Resources
•  Customers
Summary
©	
  2013	
  Amazon.com,	
  Inc.	
  and	
  its	
  affiliates.	
  	
  All	
  rights	
  reserved.	
  	
  May	
  not	
  be	
  copied,	
  modified	
  or	
  distributed	
  in	
  whole	
  or	
  in	
  part	
  without	
  the	
  express	
  consent	
  of	
  Amazon.com,	
  Inc.	
  
jscharf@amazon.com
@jim_scharf
Additional resources:
•  AWS Security Blog: http://blogs.aws.amazon.com/security/
•  AWS IAM: http://aws.amazon.com/iam/
•  AWS IAM on Twitter: @AWSIdentity
Thank You!
RegistraGon	
  opens	
  July	
  17,	
  9	
  AM	
  PDT	
  
Last	
  year,	
  it	
  sold	
  out,	
  so	
  register	
  early	
  

Más contenido relacionado

La actualidad más candente

Getting Started with AWS Lambda and the Serverless Cloud
Getting Started with AWS Lambda and the Serverless CloudGetting Started with AWS Lambda and the Serverless Cloud
Getting Started with AWS Lambda and the Serverless CloudAmazon Web Services
 
AWS re:Invent 2016: Workshop: Choose Your Own SAML Adventure: A Self-Directed...
AWS re:Invent 2016: Workshop: Choose Your Own SAML Adventure: A Self-Directed...AWS re:Invent 2016: Workshop: Choose Your Own SAML Adventure: A Self-Directed...
AWS re:Invent 2016: Workshop: Choose Your Own SAML Adventure: A Self-Directed...Amazon Web Services
 
(SEC307) A Progressive Journey Through AWS IAM Federation Options
(SEC307) A Progressive Journey Through AWS IAM Federation Options(SEC307) A Progressive Journey Through AWS IAM Federation Options
(SEC307) A Progressive Journey Through AWS IAM Federation OptionsAmazon Web Services
 
SEC302 Becoming an AWS Policy Ninja using AWS IAM and AWS Organizations
SEC302 Becoming an AWS Policy Ninja using AWS IAM and AWS OrganizationsSEC302 Becoming an AWS Policy Ninja using AWS IAM and AWS Organizations
SEC302 Becoming an AWS Policy Ninja using AWS IAM and AWS OrganizationsAmazon Web Services
 
Security best practices on AWS - Pop-up Loft TLV 2017
Security best practices on AWS - Pop-up Loft TLV 2017Security best practices on AWS - Pop-up Loft TLV 2017
Security best practices on AWS - Pop-up Loft TLV 2017Amazon Web Services
 
Dev & Test on AWS Webinar October 2017 - IL Webinar
Dev & Test on AWS Webinar October 2017 - IL WebinarDev & Test on AWS Webinar October 2017 - IL Webinar
Dev & Test on AWS Webinar October 2017 - IL WebinarAmazon Web Services
 
Network Security and Access Control in AWS
Network Security and Access Control in AWSNetwork Security and Access Control in AWS
Network Security and Access Control in AWSAmazon Web Services
 
AWS Security in Plain English – AWS Security Day
AWS Security in Plain English – AWS Security Day AWS Security in Plain English – AWS Security Day
AWS Security in Plain English – AWS Security Day Amazon Web Services
 
Unlocking Agility with the AWS Serverless Application Model (SAM) - AWS Summi...
Unlocking Agility with the AWS Serverless Application Model (SAM) - AWS Summi...Unlocking Agility with the AWS Serverless Application Model (SAM) - AWS Summi...
Unlocking Agility with the AWS Serverless Application Model (SAM) - AWS Summi...Amazon Web Services
 
Identify and Access Management: The First Step in AWS Security
Identify and Access Management: The First Step in AWS SecurityIdentify and Access Management: The First Step in AWS Security
Identify and Access Management: The First Step in AWS SecurityAmazon Web Services
 
AWS Security Best Practices (March 2017)
AWS Security Best Practices (March 2017)AWS Security Best Practices (March 2017)
AWS Security Best Practices (March 2017)Julien SIMON
 
Getting Started With AWS Security
Getting Started With AWS SecurityGetting Started With AWS Security
Getting Started With AWS SecurityAmazon Web Services
 
Security, Identity, and Access Management - Module 3 Part 1 - AWSome Day 2017
Security, Identity, and Access Management - Module 3 Part 1 - AWSome Day 2017Security, Identity, and Access Management - Module 3 Part 1 - AWSome Day 2017
Security, Identity, and Access Management - Module 3 Part 1 - AWSome Day 2017Amazon Web Services
 
Secure Amazon EC2 Environment with AWS IAM & Resource-Based Permissions (CPN2...
Secure Amazon EC2 Environment with AWS IAM & Resource-Based Permissions (CPN2...Secure Amazon EC2 Environment with AWS IAM & Resource-Based Permissions (CPN2...
Secure Amazon EC2 Environment with AWS IAM & Resource-Based Permissions (CPN2...Amazon Web Services
 
Deep Dive on Serverless App Development
Deep Dive on Serverless App DevelopmentDeep Dive on Serverless App Development
Deep Dive on Serverless App DevelopmentAmazon Web Services
 

La actualidad más candente (20)

AWSome Day | Tech Track
AWSome Day | Tech TrackAWSome Day | Tech Track
AWSome Day | Tech Track
 
AWS Black Belt Tips
AWS Black Belt TipsAWS Black Belt Tips
AWS Black Belt Tips
 
Getting Started with AWS Lambda and the Serverless Cloud
Getting Started with AWS Lambda and the Serverless CloudGetting Started with AWS Lambda and the Serverless Cloud
Getting Started with AWS Lambda and the Serverless Cloud
 
AWS re:Invent 2016: Workshop: Choose Your Own SAML Adventure: A Self-Directed...
AWS re:Invent 2016: Workshop: Choose Your Own SAML Adventure: A Self-Directed...AWS re:Invent 2016: Workshop: Choose Your Own SAML Adventure: A Self-Directed...
AWS re:Invent 2016: Workshop: Choose Your Own SAML Adventure: A Self-Directed...
 
(SEC307) A Progressive Journey Through AWS IAM Federation Options
(SEC307) A Progressive Journey Through AWS IAM Federation Options(SEC307) A Progressive Journey Through AWS IAM Federation Options
(SEC307) A Progressive Journey Through AWS IAM Federation Options
 
Security Best Practices
Security Best PracticesSecurity Best Practices
Security Best Practices
 
SEC302 Becoming an AWS Policy Ninja using AWS IAM and AWS Organizations
SEC302 Becoming an AWS Policy Ninja using AWS IAM and AWS OrganizationsSEC302 Becoming an AWS Policy Ninja using AWS IAM and AWS Organizations
SEC302 Becoming an AWS Policy Ninja using AWS IAM and AWS Organizations
 
Security best practices on AWS - Pop-up Loft TLV 2017
Security best practices on AWS - Pop-up Loft TLV 2017Security best practices on AWS - Pop-up Loft TLV 2017
Security best practices on AWS - Pop-up Loft TLV 2017
 
Dev & Test on AWS Webinar October 2017 - IL Webinar
Dev & Test on AWS Webinar October 2017 - IL WebinarDev & Test on AWS Webinar October 2017 - IL Webinar
Dev & Test on AWS Webinar October 2017 - IL Webinar
 
Network Security and Access Control in AWS
Network Security and Access Control in AWSNetwork Security and Access Control in AWS
Network Security and Access Control in AWS
 
AWS Security in Plain English – AWS Security Day
AWS Security in Plain English – AWS Security Day AWS Security in Plain English – AWS Security Day
AWS Security in Plain English – AWS Security Day
 
Unlocking Agility with the AWS Serverless Application Model (SAM) - AWS Summi...
Unlocking Agility with the AWS Serverless Application Model (SAM) - AWS Summi...Unlocking Agility with the AWS Serverless Application Model (SAM) - AWS Summi...
Unlocking Agility with the AWS Serverless Application Model (SAM) - AWS Summi...
 
Identify and Access Management: The First Step in AWS Security
Identify and Access Management: The First Step in AWS SecurityIdentify and Access Management: The First Step in AWS Security
Identify and Access Management: The First Step in AWS Security
 
AWS Security Best Practices (March 2017)
AWS Security Best Practices (March 2017)AWS Security Best Practices (March 2017)
AWS Security Best Practices (March 2017)
 
Networking and Security
Networking and SecurityNetworking and Security
Networking and Security
 
Getting Started With AWS Security
Getting Started With AWS SecurityGetting Started With AWS Security
Getting Started With AWS Security
 
Security, Identity, and Access Management - Module 3 Part 1 - AWSome Day 2017
Security, Identity, and Access Management - Module 3 Part 1 - AWSome Day 2017Security, Identity, and Access Management - Module 3 Part 1 - AWSome Day 2017
Security, Identity, and Access Management - Module 3 Part 1 - AWSome Day 2017
 
Secure Amazon EC2 Environment with AWS IAM & Resource-Based Permissions (CPN2...
Secure Amazon EC2 Environment with AWS IAM & Resource-Based Permissions (CPN2...Secure Amazon EC2 Environment with AWS IAM & Resource-Based Permissions (CPN2...
Secure Amazon EC2 Environment with AWS IAM & Resource-Based Permissions (CPN2...
 
Deep Dive on Serverless App Development
Deep Dive on Serverless App DevelopmentDeep Dive on Serverless App Development
Deep Dive on Serverless App Development
 
Storage and Compute
Storage and ComputeStorage and Compute
Storage and Compute
 

Similar a AWS IAM Guide for Access Management

AWS Webcast - Using Amazon CloudFront-Accelerate Your Static, Dynamic, Intera...
AWS Webcast - Using Amazon CloudFront-Accelerate Your Static, Dynamic, Intera...AWS Webcast - Using Amazon CloudFront-Accelerate Your Static, Dynamic, Intera...
AWS Webcast - Using Amazon CloudFront-Accelerate Your Static, Dynamic, Intera...Amazon Web Services
 
AWS Webcast - High Availability with Route 53 DNS Failover
AWS Webcast - High Availability with Route 53 DNS FailoverAWS Webcast - High Availability with Route 53 DNS Failover
AWS Webcast - High Availability with Route 53 DNS FailoverAmazon Web Services
 
AWS Webcast - Accelerating Application Performance Using In-Memory Caching in...
AWS Webcast - Accelerating Application Performance Using In-Memory Caching in...AWS Webcast - Accelerating Application Performance Using In-Memory Caching in...
AWS Webcast - Accelerating Application Performance Using In-Memory Caching in...Amazon Web Services
 
AWS Webinar - Design for Availability-13_09_10
AWS Webinar - Design for Availability-13_09_10AWS Webinar - Design for Availability-13_09_10
AWS Webinar - Design for Availability-13_09_10Amazon Web Services
 
Delivering Better Search For WordPress - AWS Webcast
Delivering Better Search For WordPress - AWS WebcastDelivering Better Search For WordPress - AWS Webcast
Delivering Better Search For WordPress - AWS WebcastMichael Bohlig
 
AWS Webinar - Intro to Amazon Cloudfront 13-09-17
AWS Webinar -  Intro to Amazon Cloudfront 13-09-17AWS Webinar -  Intro to Amazon Cloudfront 13-09-17
AWS Webinar - Intro to Amazon Cloudfront 13-09-17Amazon Web Services
 
AWS Webcast - Intro CloudFront Reporting Features
AWS Webcast - Intro CloudFront Reporting FeaturesAWS Webcast - Intro CloudFront Reporting Features
AWS Webcast - Intro CloudFront Reporting FeaturesAmazon Web Services
 
교육, 연구 개발자가 직접 전하는 AWS를 선택한 이유 Part.3 - 김재동 교사, IndiSchool (NPO) :: AWS Summi...
교육, 연구 개발자가 직접 전하는 AWS를 선택한 이유 Part.3 - 김재동 교사, IndiSchool (NPO) :: AWS Summi...교육, 연구 개발자가 직접 전하는 AWS를 선택한 이유 Part.3 - 김재동 교사, IndiSchool (NPO) :: AWS Summi...
교육, 연구 개발자가 직접 전하는 AWS를 선택한 이유 Part.3 - 김재동 교사, IndiSchool (NPO) :: AWS Summi...Amazon Web Services Korea
 
Automate your M&E workflows on AWS
Automate your M&E workflows on AWSAutomate your M&E workflows on AWS
Automate your M&E workflows on AWSAmazon Web Services
 
AWS Webcast - Design for Availability
AWS Webcast - Design for AvailabilityAWS Webcast - Design for Availability
AWS Webcast - Design for AvailabilityAmazon Web Services
 
How AWS builds Serverless services using Serverless
How AWS builds Serverless services using ServerlessHow AWS builds Serverless services using Serverless
How AWS builds Serverless services using ServerlessChris Munns
 
Using Amazon CloudSearch With Databases - CloudSearch Meetup 061913
Using Amazon CloudSearch With Databases - CloudSearch Meetup 061913Using Amazon CloudSearch With Databases - CloudSearch Meetup 061913
Using Amazon CloudSearch With Databases - CloudSearch Meetup 061913Michael Bohlig
 
AWS Webcast - Live Streaming using Amazon CloudFront and Wowza Media Server
AWS Webcast - Live Streaming using Amazon CloudFront and Wowza Media ServerAWS Webcast - Live Streaming using Amazon CloudFront and Wowza Media Server
AWS Webcast - Live Streaming using Amazon CloudFront and Wowza Media ServerAmazon Web Services
 
Amazon Route 53 - Webinar Presentation 9.16.2015
Amazon Route 53 - Webinar Presentation 9.16.2015Amazon Route 53 - Webinar Presentation 9.16.2015
Amazon Route 53 - Webinar Presentation 9.16.2015Amazon Web Services
 
AWSome Day Moscow 2014
AWSome Day Moscow 2014AWSome Day Moscow 2014
AWSome Day Moscow 2014Denis Batalov
 
AWS Webcast - Using JW Player and Amazon CloudFront to Stream HLS Video
AWS Webcast - Using JW Player and Amazon CloudFront to Stream HLS VideoAWS Webcast - Using JW Player and Amazon CloudFront to Stream HLS Video
AWS Webcast - Using JW Player and Amazon CloudFront to Stream HLS VideoAmazon Web Services
 
AWS Webcast - Amazon CloudFront Zone Apex Support & Custom SSL Domain Names
AWS Webcast - Amazon CloudFront Zone Apex Support & Custom SSL Domain Names  AWS Webcast - Amazon CloudFront Zone Apex Support & Custom SSL Domain Names
AWS Webcast - Amazon CloudFront Zone Apex Support & Custom SSL Domain Names Amazon Web Services
 
Resiliency-and-Availability-Design-Patterns-for-the-Cloud
Resiliency-and-Availability-Design-Patterns-for-the-CloudResiliency-and-Availability-Design-Patterns-for-the-Cloud
Resiliency-and-Availability-Design-Patterns-for-the-CloudAmazon Web Services
 
Now You See It, Now You Don't: Augmented Reality (AR) and Virtual Reality (VR...
Now You See It, Now You Don't: Augmented Reality (AR) and Virtual Reality (VR...Now You See It, Now You Don't: Augmented Reality (AR) and Virtual Reality (VR...
Now You See It, Now You Don't: Augmented Reality (AR) and Virtual Reality (VR...Amazon Web Services
 

Similar a AWS IAM Guide for Access Management (20)

AWS Webcast - Using Amazon CloudFront-Accelerate Your Static, Dynamic, Intera...
AWS Webcast - Using Amazon CloudFront-Accelerate Your Static, Dynamic, Intera...AWS Webcast - Using Amazon CloudFront-Accelerate Your Static, Dynamic, Intera...
AWS Webcast - Using Amazon CloudFront-Accelerate Your Static, Dynamic, Intera...
 
AWS Webcast - High Availability with Route 53 DNS Failover
AWS Webcast - High Availability with Route 53 DNS FailoverAWS Webcast - High Availability with Route 53 DNS Failover
AWS Webcast - High Availability with Route 53 DNS Failover
 
AWS Webcast - Accelerating Application Performance Using In-Memory Caching in...
AWS Webcast - Accelerating Application Performance Using In-Memory Caching in...AWS Webcast - Accelerating Application Performance Using In-Memory Caching in...
AWS Webcast - Accelerating Application Performance Using In-Memory Caching in...
 
AWS Webinar - Design for Availability-13_09_10
AWS Webinar - Design for Availability-13_09_10AWS Webinar - Design for Availability-13_09_10
AWS Webinar - Design for Availability-13_09_10
 
Delivering Better Search For WordPress - AWS Webcast
Delivering Better Search For WordPress - AWS WebcastDelivering Better Search For WordPress - AWS Webcast
Delivering Better Search For WordPress - AWS Webcast
 
AWS Webinar - Intro to Amazon Cloudfront 13-09-17
AWS Webinar -  Intro to Amazon Cloudfront 13-09-17AWS Webinar -  Intro to Amazon Cloudfront 13-09-17
AWS Webinar - Intro to Amazon Cloudfront 13-09-17
 
AWS Webcast - Intro CloudFront Reporting Features
AWS Webcast - Intro CloudFront Reporting FeaturesAWS Webcast - Intro CloudFront Reporting Features
AWS Webcast - Intro CloudFront Reporting Features
 
교육, 연구 개발자가 직접 전하는 AWS를 선택한 이유 Part.3 - 김재동 교사, IndiSchool (NPO) :: AWS Summi...
교육, 연구 개발자가 직접 전하는 AWS를 선택한 이유 Part.3 - 김재동 교사, IndiSchool (NPO) :: AWS Summi...교육, 연구 개발자가 직접 전하는 AWS를 선택한 이유 Part.3 - 김재동 교사, IndiSchool (NPO) :: AWS Summi...
교육, 연구 개발자가 직접 전하는 AWS를 선택한 이유 Part.3 - 김재동 교사, IndiSchool (NPO) :: AWS Summi...
 
Automate your M&E workflows on AWS
Automate your M&E workflows on AWSAutomate your M&E workflows on AWS
Automate your M&E workflows on AWS
 
AWS Webcast - Design for Availability
AWS Webcast - Design for AvailabilityAWS Webcast - Design for Availability
AWS Webcast - Design for Availability
 
How AWS builds Serverless services using Serverless
How AWS builds Serverless services using ServerlessHow AWS builds Serverless services using Serverless
How AWS builds Serverless services using Serverless
 
Hadoop on the Cloud
Hadoop on the CloudHadoop on the Cloud
Hadoop on the Cloud
 
Using Amazon CloudSearch With Databases - CloudSearch Meetup 061913
Using Amazon CloudSearch With Databases - CloudSearch Meetup 061913Using Amazon CloudSearch With Databases - CloudSearch Meetup 061913
Using Amazon CloudSearch With Databases - CloudSearch Meetup 061913
 
AWS Webcast - Live Streaming using Amazon CloudFront and Wowza Media Server
AWS Webcast - Live Streaming using Amazon CloudFront and Wowza Media ServerAWS Webcast - Live Streaming using Amazon CloudFront and Wowza Media Server
AWS Webcast - Live Streaming using Amazon CloudFront and Wowza Media Server
 
Amazon Route 53 - Webinar Presentation 9.16.2015
Amazon Route 53 - Webinar Presentation 9.16.2015Amazon Route 53 - Webinar Presentation 9.16.2015
Amazon Route 53 - Webinar Presentation 9.16.2015
 
AWSome Day Moscow 2014
AWSome Day Moscow 2014AWSome Day Moscow 2014
AWSome Day Moscow 2014
 
AWS Webcast - Using JW Player and Amazon CloudFront to Stream HLS Video
AWS Webcast - Using JW Player and Amazon CloudFront to Stream HLS VideoAWS Webcast - Using JW Player and Amazon CloudFront to Stream HLS Video
AWS Webcast - Using JW Player and Amazon CloudFront to Stream HLS Video
 
AWS Webcast - Amazon CloudFront Zone Apex Support & Custom SSL Domain Names
AWS Webcast - Amazon CloudFront Zone Apex Support & Custom SSL Domain Names  AWS Webcast - Amazon CloudFront Zone Apex Support & Custom SSL Domain Names
AWS Webcast - Amazon CloudFront Zone Apex Support & Custom SSL Domain Names
 
Resiliency-and-Availability-Design-Patterns-for-the-Cloud
Resiliency-and-Availability-Design-Patterns-for-the-CloudResiliency-and-Availability-Design-Patterns-for-the-Cloud
Resiliency-and-Availability-Design-Patterns-for-the-Cloud
 
Now You See It, Now You Don't: Augmented Reality (AR) and Virtual Reality (VR...
Now You See It, Now You Don't: Augmented Reality (AR) and Virtual Reality (VR...Now You See It, Now You Don't: Augmented Reality (AR) and Virtual Reality (VR...
Now You See It, Now You Don't: Augmented Reality (AR) and Virtual Reality (VR...
 

Más de CloudIDSummit

CIS 2016 Content Highlights
CIS 2016 Content HighlightsCIS 2016 Content Highlights
CIS 2016 Content HighlightsCloudIDSummit
 
Top 6 Reasons You Should Attend Cloud Identity Summit 2016
Top 6 Reasons You Should Attend Cloud Identity Summit 2016Top 6 Reasons You Should Attend Cloud Identity Summit 2016
Top 6 Reasons You Should Attend Cloud Identity Summit 2016CloudIDSummit
 
CIS 2015 Security Without Borders: Taming the Cloud and Mobile Frontier - And...
CIS 2015 Security Without Borders: Taming the Cloud and Mobile Frontier - And...CIS 2015 Security Without Borders: Taming the Cloud and Mobile Frontier - And...
CIS 2015 Security Without Borders: Taming the Cloud and Mobile Frontier - And...CloudIDSummit
 
Mobile security, identity & authentication reasons for optimism 20150607 v2
Mobile security, identity & authentication   reasons for optimism 20150607 v2Mobile security, identity & authentication   reasons for optimism 20150607 v2
Mobile security, identity & authentication reasons for optimism 20150607 v2CloudIDSummit
 
CIS 2015 Mobile Security, Identity & Authentication: Reasons for Optimism - R...
CIS 2015 Mobile Security, Identity & Authentication: Reasons for Optimism - R...CIS 2015 Mobile Security, Identity & Authentication: Reasons for Optimism - R...
CIS 2015 Mobile Security, Identity & Authentication: Reasons for Optimism - R...CloudIDSummit
 
CIS 2015 Virtual Identity: The Vision, Challenges and Experiences in Driving ...
CIS 2015 Virtual Identity: The Vision, Challenges and Experiences in Driving ...CIS 2015 Virtual Identity: The Vision, Challenges and Experiences in Driving ...
CIS 2015 Virtual Identity: The Vision, Challenges and Experiences in Driving ...CloudIDSummit
 
CIS 2015 Deploying Strong Authentication to a Global Enterprise: A Comedy in ...
CIS 2015 Deploying Strong Authentication to a Global Enterprise: A Comedy in ...CIS 2015 Deploying Strong Authentication to a Global Enterprise: A Comedy in ...
CIS 2015 Deploying Strong Authentication to a Global Enterprise: A Comedy in ...CloudIDSummit
 
CIS 2015 Without Great Security, Digital Identity is Not Worth the Electrons ...
CIS 2015 Without Great Security, Digital Identity is Not Worth the Electrons ...CIS 2015 Without Great Security, Digital Identity is Not Worth the Electrons ...
CIS 2015 Without Great Security, Digital Identity is Not Worth the Electrons ...CloudIDSummit
 
CIS 2015 Mergers & Acquisitions in a Cloud Enabled World - Brian Puhl
CIS 2015 Mergers & Acquisitions in a Cloud Enabled World - Brian PuhlCIS 2015 Mergers & Acquisitions in a Cloud Enabled World - Brian Puhl
CIS 2015 Mergers & Acquisitions in a Cloud Enabled World - Brian PuhlCloudIDSummit
 
CIS 2015 IoT and IDM in your Mobile Enterprise - Brian Katz
CIS 2015 IoT and IDM  in your Mobile Enterprise - Brian KatzCIS 2015 IoT and IDM  in your Mobile Enterprise - Brian Katz
CIS 2015 IoT and IDM in your Mobile Enterprise - Brian KatzCloudIDSummit
 
CIS 2015 Practical Deployments Enterprise Cloud Access Management Platform - ...
CIS 2015 Practical Deployments Enterprise Cloud Access Management Platform - ...CIS 2015 Practical Deployments Enterprise Cloud Access Management Platform - ...
CIS 2015 Practical Deployments Enterprise Cloud Access Management Platform - ...CloudIDSummit
 
CIS 2015 What I Learned From Pitching IAM To My CIO - Steve Tout
CIS 2015 What I Learned From Pitching IAM To My CIO - Steve ToutCIS 2015 What I Learned From Pitching IAM To My CIO - Steve Tout
CIS 2015 What I Learned From Pitching IAM To My CIO - Steve ToutCloudIDSummit
 
CIS 2015 How to secure the Internet of Things? Hannes Tschofenig
CIS 2015 How to secure the Internet of Things? Hannes TschofenigCIS 2015 How to secure the Internet of Things? Hannes Tschofenig
CIS 2015 How to secure the Internet of Things? Hannes TschofenigCloudIDSummit
 
CIS 2015 The IDaaS Dating Game - Sean Deuby
CIS 2015 The IDaaS Dating Game - Sean DeubyCIS 2015 The IDaaS Dating Game - Sean Deuby
CIS 2015 The IDaaS Dating Game - Sean DeubyCloudIDSummit
 
CIS 2015 SSO for Mobile and Web Apps Ashish Jain
CIS 2015 SSO for Mobile and Web Apps Ashish JainCIS 2015 SSO for Mobile and Web Apps Ashish Jain
CIS 2015 SSO for Mobile and Web Apps Ashish JainCloudIDSummit
 
The Industrial Internet, the Identity of Everything and the Industrial Enterp...
The Industrial Internet, the Identity of Everything and the Industrial Enterp...The Industrial Internet, the Identity of Everything and the Industrial Enterp...
The Industrial Internet, the Identity of Everything and the Industrial Enterp...CloudIDSummit
 
CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John Dasilva
CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John DasilvaCIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John Dasilva
CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John DasilvaCloudIDSummit
 
CIS 2015 Session Management at Scale - Scott Tomilson & Jamshid Khosravian
CIS 2015  Session Management at Scale - Scott Tomilson & Jamshid KhosravianCIS 2015  Session Management at Scale - Scott Tomilson & Jamshid Khosravian
CIS 2015 Session Management at Scale - Scott Tomilson & Jamshid KhosravianCloudIDSummit
 
CIS 2015 So you want to SSO … Scott Tomilson & John Dasilva
CIS 2015 So you want to SSO … Scott Tomilson & John DasilvaCIS 2015 So you want to SSO … Scott Tomilson & John Dasilva
CIS 2015 So you want to SSO … Scott Tomilson & John DasilvaCloudIDSummit
 
CIS 2015 Identity Relationship Management in the Internet of Things
CIS 2015 Identity Relationship Management in the Internet of ThingsCIS 2015 Identity Relationship Management in the Internet of Things
CIS 2015 Identity Relationship Management in the Internet of ThingsCloudIDSummit
 

Más de CloudIDSummit (20)

CIS 2016 Content Highlights
CIS 2016 Content HighlightsCIS 2016 Content Highlights
CIS 2016 Content Highlights
 
Top 6 Reasons You Should Attend Cloud Identity Summit 2016
Top 6 Reasons You Should Attend Cloud Identity Summit 2016Top 6 Reasons You Should Attend Cloud Identity Summit 2016
Top 6 Reasons You Should Attend Cloud Identity Summit 2016
 
CIS 2015 Security Without Borders: Taming the Cloud and Mobile Frontier - And...
CIS 2015 Security Without Borders: Taming the Cloud and Mobile Frontier - And...CIS 2015 Security Without Borders: Taming the Cloud and Mobile Frontier - And...
CIS 2015 Security Without Borders: Taming the Cloud and Mobile Frontier - And...
 
Mobile security, identity & authentication reasons for optimism 20150607 v2
Mobile security, identity & authentication   reasons for optimism 20150607 v2Mobile security, identity & authentication   reasons for optimism 20150607 v2
Mobile security, identity & authentication reasons for optimism 20150607 v2
 
CIS 2015 Mobile Security, Identity & Authentication: Reasons for Optimism - R...
CIS 2015 Mobile Security, Identity & Authentication: Reasons for Optimism - R...CIS 2015 Mobile Security, Identity & Authentication: Reasons for Optimism - R...
CIS 2015 Mobile Security, Identity & Authentication: Reasons for Optimism - R...
 
CIS 2015 Virtual Identity: The Vision, Challenges and Experiences in Driving ...
CIS 2015 Virtual Identity: The Vision, Challenges and Experiences in Driving ...CIS 2015 Virtual Identity: The Vision, Challenges and Experiences in Driving ...
CIS 2015 Virtual Identity: The Vision, Challenges and Experiences in Driving ...
 
CIS 2015 Deploying Strong Authentication to a Global Enterprise: A Comedy in ...
CIS 2015 Deploying Strong Authentication to a Global Enterprise: A Comedy in ...CIS 2015 Deploying Strong Authentication to a Global Enterprise: A Comedy in ...
CIS 2015 Deploying Strong Authentication to a Global Enterprise: A Comedy in ...
 
CIS 2015 Without Great Security, Digital Identity is Not Worth the Electrons ...
CIS 2015 Without Great Security, Digital Identity is Not Worth the Electrons ...CIS 2015 Without Great Security, Digital Identity is Not Worth the Electrons ...
CIS 2015 Without Great Security, Digital Identity is Not Worth the Electrons ...
 
CIS 2015 Mergers & Acquisitions in a Cloud Enabled World - Brian Puhl
CIS 2015 Mergers & Acquisitions in a Cloud Enabled World - Brian PuhlCIS 2015 Mergers & Acquisitions in a Cloud Enabled World - Brian Puhl
CIS 2015 Mergers & Acquisitions in a Cloud Enabled World - Brian Puhl
 
CIS 2015 IoT and IDM in your Mobile Enterprise - Brian Katz
CIS 2015 IoT and IDM  in your Mobile Enterprise - Brian KatzCIS 2015 IoT and IDM  in your Mobile Enterprise - Brian Katz
CIS 2015 IoT and IDM in your Mobile Enterprise - Brian Katz
 
CIS 2015 Practical Deployments Enterprise Cloud Access Management Platform - ...
CIS 2015 Practical Deployments Enterprise Cloud Access Management Platform - ...CIS 2015 Practical Deployments Enterprise Cloud Access Management Platform - ...
CIS 2015 Practical Deployments Enterprise Cloud Access Management Platform - ...
 
CIS 2015 What I Learned From Pitching IAM To My CIO - Steve Tout
CIS 2015 What I Learned From Pitching IAM To My CIO - Steve ToutCIS 2015 What I Learned From Pitching IAM To My CIO - Steve Tout
CIS 2015 What I Learned From Pitching IAM To My CIO - Steve Tout
 
CIS 2015 How to secure the Internet of Things? Hannes Tschofenig
CIS 2015 How to secure the Internet of Things? Hannes TschofenigCIS 2015 How to secure the Internet of Things? Hannes Tschofenig
CIS 2015 How to secure the Internet of Things? Hannes Tschofenig
 
CIS 2015 The IDaaS Dating Game - Sean Deuby
CIS 2015 The IDaaS Dating Game - Sean DeubyCIS 2015 The IDaaS Dating Game - Sean Deuby
CIS 2015 The IDaaS Dating Game - Sean Deuby
 
CIS 2015 SSO for Mobile and Web Apps Ashish Jain
CIS 2015 SSO for Mobile and Web Apps Ashish JainCIS 2015 SSO for Mobile and Web Apps Ashish Jain
CIS 2015 SSO for Mobile and Web Apps Ashish Jain
 
The Industrial Internet, the Identity of Everything and the Industrial Enterp...
The Industrial Internet, the Identity of Everything and the Industrial Enterp...The Industrial Internet, the Identity of Everything and the Industrial Enterp...
The Industrial Internet, the Identity of Everything and the Industrial Enterp...
 
CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John Dasilva
CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John DasilvaCIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John Dasilva
CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John Dasilva
 
CIS 2015 Session Management at Scale - Scott Tomilson & Jamshid Khosravian
CIS 2015  Session Management at Scale - Scott Tomilson & Jamshid KhosravianCIS 2015  Session Management at Scale - Scott Tomilson & Jamshid Khosravian
CIS 2015 Session Management at Scale - Scott Tomilson & Jamshid Khosravian
 
CIS 2015 So you want to SSO … Scott Tomilson & John Dasilva
CIS 2015 So you want to SSO … Scott Tomilson & John DasilvaCIS 2015 So you want to SSO … Scott Tomilson & John Dasilva
CIS 2015 So you want to SSO … Scott Tomilson & John Dasilva
 
CIS 2015 Identity Relationship Management in the Internet of Things
CIS 2015 Identity Relationship Management in the Internet of ThingsCIS 2015 Identity Relationship Management in the Internet of Things
CIS 2015 Identity Relationship Management in the Internet of Things
 

Último

Revolutionalizing Travel: A VacAI Update
Revolutionalizing Travel: A VacAI UpdateRevolutionalizing Travel: A VacAI Update
Revolutionalizing Travel: A VacAI Updatejoymorrison10
 
8377087607 Full Enjoy @24/7 Call Girls in INA Market Dilli Hatt Delhi NCR
8377087607 Full Enjoy @24/7 Call Girls in INA Market Dilli Hatt Delhi NCR8377087607 Full Enjoy @24/7 Call Girls in INA Market Dilli Hatt Delhi NCR
8377087607 Full Enjoy @24/7 Call Girls in INA Market Dilli Hatt Delhi NCRdollysharma2066
 
Exploring Sicily Your Comprehensive Ebook Travel Guide
Exploring Sicily Your Comprehensive Ebook Travel GuideExploring Sicily Your Comprehensive Ebook Travel Guide
Exploring Sicily Your Comprehensive Ebook Travel GuideTime for Sicily
 
Authentic Travel Experience 2024 Greg DeShields.pptx
Authentic Travel Experience 2024 Greg DeShields.pptxAuthentic Travel Experience 2024 Greg DeShields.pptx
Authentic Travel Experience 2024 Greg DeShields.pptxGregory DeShields
 
5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)
5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)
5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)Mazie Garcia
 
69 Girls ✠ 9599264170 ✠ Call Girls In East Of Kailash (VIP)
69 Girls ✠ 9599264170 ✠ Call Girls In East Of Kailash (VIP)69 Girls ✠ 9599264170 ✠ Call Girls In East Of Kailash (VIP)
69 Girls ✠ 9599264170 ✠ Call Girls In East Of Kailash (VIP)Escort Service
 
Inspirational Quotes About Italy and Food
Inspirational Quotes About Italy and FoodInspirational Quotes About Italy and Food
Inspirational Quotes About Italy and FoodKasia Chojecki
 
Apply Indian E-Visa Process Online (Evisa)
Apply Indian E-Visa Process Online (Evisa)Apply Indian E-Visa Process Online (Evisa)
Apply Indian E-Visa Process Online (Evisa)RanjeetKumar108130
 
Hoi An Ancient Town, Vietnam (越南 會安古鎮).ppsx
Hoi An Ancient Town, Vietnam (越南 會安古鎮).ppsxHoi An Ancient Town, Vietnam (越南 會安古鎮).ppsx
Hoi An Ancient Town, Vietnam (越南 會安古鎮).ppsxChung Yen Chang
 
Aeromexico Airlines Flight Name Change Policy
Aeromexico Airlines Flight Name Change PolicyAeromexico Airlines Flight Name Change Policy
Aeromexico Airlines Flight Name Change PolicyFlyFairTravels
 
Moroccan Architecture presentation ( Omar & Yasine ).pptx
Moroccan Architecture presentation ( Omar & Yasine ).pptxMoroccan Architecture presentation ( Omar & Yasine ).pptx
Moroccan Architecture presentation ( Omar & Yasine ).pptxOmarOuazzani1
 
Haitian culture and stuff and places and food and travel.pptx
Haitian culture and stuff and places and food and travel.pptxHaitian culture and stuff and places and food and travel.pptx
Haitian culture and stuff and places and food and travel.pptxhxhlixia
 
Where to Stay in Lagos, Portugal.pptxasd
Where to Stay in Lagos, Portugal.pptxasdWhere to Stay in Lagos, Portugal.pptxasd
Where to Stay in Lagos, Portugal.pptxasdusmanghaniwixpatriot
 
"Fly with Ease: Booking Your Flights with Air Europa"
"Fly with Ease: Booking Your Flights with Air Europa""Fly with Ease: Booking Your Flights with Air Europa"
"Fly with Ease: Booking Your Flights with Air Europa"flyn goo
 
How Safe Is It To Witness Whales In Maui’s Waters
How Safe Is It To Witness Whales In Maui’s WatersHow Safe Is It To Witness Whales In Maui’s Waters
How Safe Is It To Witness Whales In Maui’s WatersMakena Coast Charters
 
Italia Lucca 1 Un tesoro nascosto tra le sue mura
Italia Lucca 1 Un tesoro nascosto tra le sue muraItalia Lucca 1 Un tesoro nascosto tra le sue mura
Italia Lucca 1 Un tesoro nascosto tra le sue murasandamichaela *
 
(8264348440) 🔝 Call Girls In Nand Nagri 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Nand Nagri 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Nand Nagri 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Nand Nagri 🔝 Delhi NCRsoniya singh
 
Dubai Call Girls O528786472 Call Girls Dubai Big Juicy
Dubai Call Girls O528786472 Call Girls Dubai Big JuicyDubai Call Girls O528786472 Call Girls Dubai Big Juicy
Dubai Call Girls O528786472 Call Girls Dubai Big Juicyhf8803863
 

Último (20)

Revolutionalizing Travel: A VacAI Update
Revolutionalizing Travel: A VacAI UpdateRevolutionalizing Travel: A VacAI Update
Revolutionalizing Travel: A VacAI Update
 
8377087607 Full Enjoy @24/7 Call Girls in INA Market Dilli Hatt Delhi NCR
8377087607 Full Enjoy @24/7 Call Girls in INA Market Dilli Hatt Delhi NCR8377087607 Full Enjoy @24/7 Call Girls in INA Market Dilli Hatt Delhi NCR
8377087607 Full Enjoy @24/7 Call Girls in INA Market Dilli Hatt Delhi NCR
 
Exploring Sicily Your Comprehensive Ebook Travel Guide
Exploring Sicily Your Comprehensive Ebook Travel GuideExploring Sicily Your Comprehensive Ebook Travel Guide
Exploring Sicily Your Comprehensive Ebook Travel Guide
 
Authentic Travel Experience 2024 Greg DeShields.pptx
Authentic Travel Experience 2024 Greg DeShields.pptxAuthentic Travel Experience 2024 Greg DeShields.pptx
Authentic Travel Experience 2024 Greg DeShields.pptx
 
5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)
5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)
5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)
 
Enjoy ➥8448380779▻ Call Girls In Sector 74 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 74 Noida Escorts Delhi NCREnjoy ➥8448380779▻ Call Girls In Sector 74 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 74 Noida Escorts Delhi NCR
 
69 Girls ✠ 9599264170 ✠ Call Girls In East Of Kailash (VIP)
69 Girls ✠ 9599264170 ✠ Call Girls In East Of Kailash (VIP)69 Girls ✠ 9599264170 ✠ Call Girls In East Of Kailash (VIP)
69 Girls ✠ 9599264170 ✠ Call Girls In East Of Kailash (VIP)
 
Inspirational Quotes About Italy and Food
Inspirational Quotes About Italy and FoodInspirational Quotes About Italy and Food
Inspirational Quotes About Italy and Food
 
Enjoy ➥8448380779▻ Call Girls In Sector 62 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 62 Noida Escorts Delhi NCREnjoy ➥8448380779▻ Call Girls In Sector 62 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 62 Noida Escorts Delhi NCR
 
Apply Indian E-Visa Process Online (Evisa)
Apply Indian E-Visa Process Online (Evisa)Apply Indian E-Visa Process Online (Evisa)
Apply Indian E-Visa Process Online (Evisa)
 
Hoi An Ancient Town, Vietnam (越南 會安古鎮).ppsx
Hoi An Ancient Town, Vietnam (越南 會安古鎮).ppsxHoi An Ancient Town, Vietnam (越南 會安古鎮).ppsx
Hoi An Ancient Town, Vietnam (越南 會安古鎮).ppsx
 
Aeromexico Airlines Flight Name Change Policy
Aeromexico Airlines Flight Name Change PolicyAeromexico Airlines Flight Name Change Policy
Aeromexico Airlines Flight Name Change Policy
 
Moroccan Architecture presentation ( Omar & Yasine ).pptx
Moroccan Architecture presentation ( Omar & Yasine ).pptxMoroccan Architecture presentation ( Omar & Yasine ).pptx
Moroccan Architecture presentation ( Omar & Yasine ).pptx
 
Haitian culture and stuff and places and food and travel.pptx
Haitian culture and stuff and places and food and travel.pptxHaitian culture and stuff and places and food and travel.pptx
Haitian culture and stuff and places and food and travel.pptx
 
Where to Stay in Lagos, Portugal.pptxasd
Where to Stay in Lagos, Portugal.pptxasdWhere to Stay in Lagos, Portugal.pptxasd
Where to Stay in Lagos, Portugal.pptxasd
 
"Fly with Ease: Booking Your Flights with Air Europa"
"Fly with Ease: Booking Your Flights with Air Europa""Fly with Ease: Booking Your Flights with Air Europa"
"Fly with Ease: Booking Your Flights with Air Europa"
 
How Safe Is It To Witness Whales In Maui’s Waters
How Safe Is It To Witness Whales In Maui’s WatersHow Safe Is It To Witness Whales In Maui’s Waters
How Safe Is It To Witness Whales In Maui’s Waters
 
Italia Lucca 1 Un tesoro nascosto tra le sue mura
Italia Lucca 1 Un tesoro nascosto tra le sue muraItalia Lucca 1 Un tesoro nascosto tra le sue mura
Italia Lucca 1 Un tesoro nascosto tra le sue mura
 
(8264348440) 🔝 Call Girls In Nand Nagri 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Nand Nagri 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Nand Nagri 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Nand Nagri 🔝 Delhi NCR
 
Dubai Call Girls O528786472 Call Girls Dubai Big Juicy
Dubai Call Girls O528786472 Call Girls Dubai Big JuicyDubai Call Girls O528786472 Call Girls Dubai Big Juicy
Dubai Call Girls O528786472 Call Girls Dubai Big Juicy
 

AWS IAM Guide for Access Management

  • 1. AWS Identity and Access Management Jim Scharf 7/11/2013
  • 2. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Jim Scharf Director, AWS Identity and Access Management Joined AWS in 2004 Own •  AWS Identity and Access Management •  Authentication, Authorization •  Federation Introductions
  • 3. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Enable businesses and developers to use web services* to build scalable, sophisticated applications. *What people now call “the cloud” AWS Mission
  • 4. Free steak campaign Facebook page Mars exploration operations Consumer social app Gene sequencing Marketing web site Interactive TV apps Financial markets analytics Web site & media sharing Disaster recovery Media streaming Web and mobile apps Diverse  Customers,  Wide  Range  of  Use  Cases   ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  
  • 5. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Mission-­‐criFcal   Projects     Mars  Rover  Image   processing   Video  Streaming   for  Landing   Scale  up  as   needed   Highly  Parallel   Processing   Whole  World   Watching   One-­‐Time  Event   Mars  Rovers  OperaFons
  • 6. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Panoramas  of  5  Gigapixels,  created  on  AWS  in  just  5  minutes!   Curiosity ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  
  • 7. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Daily  Mars  Rover  Data  Processing  Window  (2  hours)   Serial  Process   Upload  Plan   Pre-­‐cloud:   Parallel   Process   Upload  Plan   Cloud:   Increased  available  mission  planning  Fme  by  1.5  hours!   Mission  Data  Processing
  • 8. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   More on NASA & AWS AWS  Re:Invent  Conference,  2012  Keynote  Video   hp://youtu.be/8FJ5DBLSFe4?t=11m58s    
  • 9. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Compute   Networking   Storage  &    CDN   Amazon  EC2   Amazon  ElasFc  MapReduce   Amazon  ElasFc  Load  Balancer     Amazon  Route  53   Amazon  Virtual  Private  Cloud   AWS  Direct  Connect     Amazon  S3   Amazon  Glacier   Amazon  EBS   AWS  Import/Export   Amazon  CloudFront     Database   App  Services   Management   Amazon  RDS   Amazon  DynamoDB   Amazon  ElasFCache   Amazon  Redshie     Amazon  CloudSearch   Amazon  SWF   Amazon  SQS  (Queues)   Amazon  SNS  (NoFficaFons)   Amazon  SES  (Email)   Amazon  ElasFc  Transcoder     AWS  IAM   Amazon  CloudWatch   AWS  ElasFc  Beanstalk   AWS  CloudFormaFon   AWS  Data  Pipeline   AWS  OpsWorks   AWS  CloudHSM   AWS  Trusted  Advisor   AWS  Marketplace   AWS Services
  • 10. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Access control for AWS services and resources AWS Identity and Access Management
  • 11. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  
  • 12. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Difference #1
  • 13. Image  courtesy  of:    hp://imgsrc.hubblesite.org/hu/db/images/hs-­‐2005-­‐01-­‐a-­‐full_jpg.jpg   ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  
  • 14. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   AWS Scale •  $5.2B e-commerce company •  7,800 employees •  A whole lot of servers! Every day (on average), AWS adds server capacity equivalent to that entire $5.2B enterprise
  • 15. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Trillions Resources
  • 16. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Million+ Requests/Second  
  • 17. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Hundreds of Thousands Customers in 190 countries each with one to millions of identities
  • 18. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Lots! Servers  
  • 19. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Global
  • 20. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Difference #2
  • 21. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Resources
  • 22. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Cloud Services Amazon   EC2  
  • 23. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Instance O/S
  • 24. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Cloud Services Amazon   EC2   Amazon   S3   Amazon   ElasFc   MapReduce   AWS   Storage   Gateway   Amazon   DynamoDB   Amazon   RDS   Amazon   ElasFCache   Amazon   Route  53   Amazon   VPC   Amazon   CloudFront   Amazon   CloudWatch   Amazon   ElasFc   Beanstalk   AWS   CloudFormaFon   AWS  IAM   Amazon   SQS   Amazon   SES   Amazon   SNS   Amazon   CloudSearch   Amazon   SWF   Amazon Redshift OpsWorks   Amazon  ElasFc   Transcoder  
  • 25. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Cloud Resources Amazon   EC2   Amazon   S3   Amazon   ElasFc   MapReduce   AWS   Storage   Gateway   Amazon   DynamoDB   Amazon   RDS   Amazon   ElasFCache   Amazon   Route  53   Amazon   VPC   Amazon   CloudFront   Amazon   CloudWatch   Amazon   ElasFc   Beanstalk   AWS   CloudFormaFon   AWS  IAM   Amazon   SQS   Amazon   SES   Amazon   SNS   Amazon   CloudSearch   Amazon   SWF   Amazon Redshift OpsWorks   Amazon  ElasFc   Transcoder   Instances   Files   AMIs   Spot  Instances   Volumes   Messages   Snapshots   Security  Groups   ElasFc  IPs   Placement  Groups   Users   Groups   Roles   Load  Balancers   Autoscaling  Groups   Network  Interfaces   Queues   Topics   Domains   Workflows   ApplicaFons   Templates   DistribuFons   Buckets   Stacks   Apps   Layers   Clusters  
  • 26. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   AWS Marketplace
  • 27. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Difference #3
  • 28. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Customers •  Individual Developers •  Students
  • 29. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Hear about AWS
  • 30. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Create Account
  • 31. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Innovate!
  • 32. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Customers •  Individual Developers •  Students •  Startups •  SMBs
  • 33. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   IAM •  Users, Groups, Permissions –  Individual security credentials –  Secure by default –  Grant least privilege •  Easy to use –  Graphical user interface –  Ability to script/automate (CLI & API)
  • 34. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Customers •  Individual Developers •  Students •  Startups •  SMBs •  Enterprises •  Government Agencies
  • 35. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Control •  AWS Multi-Factor Authentication –  Hardware tokens –  Smartphone app tokens •  Credential management policies •  Control billing, support, and AWS Marketplace purchases
  • 36. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   •  HIPAA •  SOC 1/SSAE 16/ISAE 3402 (formerly SAS70) •  SOC 2 •  SOC 3 •  PCI DSS Level 1 •  ISO 27001 •  FedRAMP •  DIACAP and FISMA •  ITAR •  FIPS 140-2 •  CSA •  MPAA Compliance
  • 37. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Federation •  AWS Websites and/or APIs as relying party •  Pre-packaged sample: Windows Active Directory as identity provider SSO   AcFve  Directory  
  • 38. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Federation •  Partners are critical http://www.xceedium.com/xsuite/xsuite-for-amazon-web-services http://www.okta.com/aws/ http://www.symplified.com/solutions/single-sign-on-sso https://www.pingidentity.com/products/pingfederate/ •  More federation support coming…
  • 39. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Customers •  Individual Developers •  Students •  Startups •  SMBs •  Enterprises •  Government Agencies •  Mobile Developers
  • 40. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Web Identity Federation •  App sign-in using 3rd party identity providers –  –  Facebook –  Google (using OpenID Connect) •  No server-side code required
  • 41. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Web Identity Federation US-EAST-1 AWS Services STS   Access  AWS  Resources   IdenFty   Provider   Assume  Role   Amazon  S3   Amazon   DynamoDB  
  • 42. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   Customer Evolution Username  &   Password   IAM   Management  UI,  CLI,  API   MulF-­‐Factor  AuthenFcaFon   FederaFon  &  SSO     Password  Strength  Policy   AWS  Marketplace  Control   Enterprise   Joe   Startup/   SMB   No  addiGonal  charge   Mobile  
  • 43. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   •  Scale •  Resources •  Customers Summary
  • 44. ©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.   jscharf@amazon.com @jim_scharf Additional resources: •  AWS Security Blog: http://blogs.aws.amazon.com/security/ •  AWS IAM: http://aws.amazon.com/iam/ •  AWS IAM on Twitter: @AWSIdentity Thank You! RegistraGon  opens  July  17,  9  AM  PDT   Last  year,  it  sold  out,  so  register  early