Governance
Resource Access Manager (RAM)
- Share resources with other AWS accounts
Cross Account Role Access
- Define an IAM Role for another account to access
- Define which accounts can access this IAM Role
- Use AWS STS to retrieve credentials and impersonate the IAM Role you have access to (AssumeRole API)
- Temporary credentials can be valid between 15 minutes to 1 hour
AWS AppConfig
- ??
Directory Service
- Fully managed service of active Directory
- Two components
- Microsoft AD
- Connector AD
Compute Optimizer
- ?