Which strategy will meet these requirements?

1 Comment

  1. Christian
    Author

    I sort that the answer is:
    Pass an attribute for DevelopmentUnit as an AWS Security Token Service (AWS STS) session tag during SAML federation. Update the IAM policy for the developers’ assumed IAM role with a deny action and a StringNotEquals condition for the DevelopmentUnit resource tag and aws:PrincipalTag/DevelopmentUnit.

Leave a Reply

Your email address will not be published. Required fields are marked *

two × two =