Which strategy will meet these requirements?

1 Comment

  1. Lucas
    Author

    I outline that the answer is:
    Pass an attribute for DevelopmentUnit as an AWS Security Token Service (AWS STS) session tag during SAML federation. Update the IAM policy for the developers’ assumed IAM role with a deny action and a StringNotEquals condition for the DevelopmentUnit resource tag and aws:PrincipalTag/ DevelopmentUnit.

Leave a Reply

Your email address will not be published. Required fields are marked *

nine + 10 =