{"repo":"PeterBengtson/AFT-SSO-account-configuration","free":true,"listed":false,"github":"https://github.com/PeterBengtson/AFT-SSO-account-configuration","clone":"git clone https://github.com/PeterBengtson/AFT-SSO-account-configuration.git","description":"Allows you to use AFT (Account Factory for Terraform) to declaratively specify SSO Group and SSO User access to an account.","language":"Python","stars":25,"topics":["aws","sso","open-source"],"license":"MIT","category":"auth-billing-email","readme_excerpt":"SSO Account Configuration Allows you to use AFT (Account Factory for Terraform) to declaratively specify SSO Group and SSO User access to an account in the following way: Furthermore, if you provide a value for the parameter CloudAdministrationGroupName , this SSO group will be automatically added to all accounts, with the permissions given in the parameter CloudAdministrationGroupPermissionSets , defaulting to \"AWSAdministratorAccess,AWSReadOnlyAccess\" . NB: Any group or user assignments not explicitly mentioned will be deleted automatically, except for the groups AWSSecurityAuditors , AWSControlTowerAdmins and AWSSecurityAuditPowerUsers . They are assigned by Service Catalog when Control Tower creates an account and should be left as is. Installation Deploy this SAM project in the organisation account, in your main region. All that's required is Subsequent deploys are done just by sam build && sam deploy . To activate, put the following in your aft-global-customizations repo, in pre-api-helpers.sh in the api helpers directory. Substitute the --topic-arn value for the SNS topic. Protecting the settings You will probably want to include something like the following in an SCP to protect the AFT settings from being tampered with: You can add the following to the same SCP to block users of a permission set from using or even seeing the values of the SSO parameters in their own accounts. Substitute DeveloperAccess with the name of your own permission set, but keep the prefix and ","default_branch":null,"files":null,"tree":[],"storefront":"/r/PeterBengtson","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/PeterBengtson/AFT-SSO-account-configuration/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}