Implementing Enterprise-managed IAM: An SRE Team’s Success Story

10:40 pm
October 24, 2023

Enterprise-managed identity and access management (IAM) systems provide cloud administrators with the ability to centrally configure access and security settings for an entire organization. In this case study, we explore how a site reliability engineering (SRE) team successfully implemented and managed their access across an enterprise.

Case Study

A large banking client has a centralized SRE team responsible for managing operations for all resources in the organization. To authenticate users to IBM Cloud enterprise accounts, the client uses federation. Additionally, all teams in the organization use Kubernetes and IBM Cloud Databases resources. The SRE team needs operational access to these resources across all teams and accounts.

Initially, manually managing access for the SRE team across a growing number of accounts was time-consuming and prone to errors. The access setup also did not meet certain audit controls, as child account administrators could update assigned access. To address these challenges, the client adopted enterprise-managed IAM templates.

By defining access for the SRE team using IAM templates and assigning them to the organization’s accounts, the client transformed the access management process from an ongoing effort to a one-time setup activity. This ensured that SRE access was automatically included in both existing and newly created accounts, and it could no longer be modified by child account administrators.

In this article, we will provide step-by-step instructions on how to implement a similar solution in your organization.

Prerequisites

  1. Be in the root enterprise account.
  2. The enterprise user performing this task should have the Template Administrator and Template Assignment Administrator roles on IAM services, as well as at least the Viewer role on the Enterprise service.
  3. Ensure that child accounts have enabled the enterprise-managed IAM setting.

Solution

To implement the enterprise-managed IAM solution for the SRE team, follow these steps:

  1. Create a trusted profile template.
  2. Add a trust relationship.
  3. Add access policy templates.
  4. Review and commit the trusted profile template.
  5. Assign the trusted profile template.

To update the template and assignment, follow these steps:

  1. Create a new template version.
  2. Add an additional access policy template.
  3. Review and commit the trusted profile template.
  4. Update the existing assignment to the new version.

Steps to create and assign a template

Follow the steps below to create and assign a trusted profile template for the SRE team:

  1. Go to Manage > Access (IAM). In the Enterprise section, click Templates > Trusted Profiles > Create. Create a trusted profile template for the SRE team.
  2. Add a trust relationship to dynamically add the SRE team to the trusted profile based on your Identity provider (IdP).
  3. Go to the Access tab to create access policies for the IBM Cloud Kubernetes Service and IBM Cloud Databases for MongoDB.
  4. Review and commit the trusted profile and policy templates to prevent changes.
  5. Assign the trusted profile template to the account group.

After completing the assignment, the SRE team members will have the necessary access to perform their duties in the accounts under the assigned group.

Conclusion

Implementing enterprise-managed IAM can significantly simplify access management for organizations. By using IAM templates and assigning them to accounts, the SRE team at the banking client was able to streamline access provisioning and ensure consistent access control across multiple accounts. This one-time setup activity saved time, reduced errors, and enhanced security.

FAQs

1. What is enterprise-managed IAM?

Enterprise-managed IAM enables cloud administrators to centrally configure access and security settings for their organization. It provides a streamlined approach to access management and ensures consistent control and security across accounts.

2. How does enterprise-managed IAM benefit SRE teams?

Enterprise-managed IAM simplifies access management for SRE teams by allowing them to define access through templates and assign them to relevant accounts. This eliminates the need for manual access setup and ensures that access control remains consistent and enforced.

3. Can the assigned access be updated by child account administrators?

No, with enterprise-managed IAM, the assigned access cannot be updated by child account administrators, ensuring that access control remains consistent and secure.


Share:

More in this category ...

12:19 am April 24, 2024

5 steps for enforcing alternate control for your group

7:34 pm April 23, 2024

Crypto.com delays South Korea release amid regulatory hurdles

7:22 pm April 23, 2024

XRP Wallets Holding At Least 1 Million Coins Nears All-Time High As Sentiment Improves

12:40 pm April 23, 2024

Artificial Intelligence this Earth Day: Top alternatives to advance sustainability tasks

12:22 pm April 23, 2024

SEC seeks $5.3 billion from Terraform Labs and Do Kwon

7:24 am April 23, 2024

BNB Price Reclaims $600 and Bulls Could Now Aim For New 2024 High

5:10 am April 23, 2024

Ledger Live brings crypto swaps to customers by way of MoonPay partnership

1:00 am April 23, 2024

Deployable structure on IBM Cloud: Simplifying gadget deployment

7:27 pm April 22, 2024

Analyst Thinks Dream Milestone Could Be Hit In Coming Weeks

2:45 pm April 22, 2024

Figure Markets CEO confirms FTX’s public sale of ultimate locked Solana (SOL)

7:30 am April 22, 2024

DOGE Price Prediction – Dogecoin Recovery Could Stall At $0.170

7:26 pm April 21, 2024

Ethereum Enters Accumulation Phase

5:07 pm April 21, 2024

Bitbot positive aspects as Ape Terminal cancels ZKasino IDO

2:00 pm April 21, 2024

Building the human firewall: Navigating behavioral exchange in safety consciousness and tradition

7:28 am April 21, 2024

Bitcoin Users Spend Record $2.4 Million On Block 840,000

2:21 am April 21, 2024

Maximize the facility of your strains of protection towards cyber-attacks with IBM Storage FlashDevice and IBM Storage Defender

7:31 pm April 20, 2024

Fourth Bitcoin Halving Completed – Here Are The Implications

7:29 pm April 20, 2024

TRON traders making an allowance for TON and Bitbot amid SEC lawsuit towards Justin Sun

2:42 pm April 20, 2024

Probable Root Cause: Accelerating incident remediation with causal Computational Intelligence 

12:15 pm April 20, 2024

Telegram to tokenize emojis and stickers as NFTs on TON blockchain

7:31 am April 20, 2024

Relay Chain Replacement And 10M DOT Prize Incentive

5:03 am April 20, 2024

Hedgey Protocol loses $44.7M in twin cyber assaults

3:03 am April 20, 2024

The adventure to a mature asset control machine

7:28 pm April 19, 2024

320 Million USDT Inflow Could Ignite Price Surge

3:24 pm April 19, 2024

Live from TOKEN2049: Telos broadcasts Ethereum Layer 2 partnership with Ponos Technology

2:39 pm April 19, 2024

JPMorgan CEO calls Bitcoin a ‘Ponzi Scheme’ regardless of JPMorgan’s involvement in Bitcoin ETFs

7:30 am April 19, 2024

BNB Price May Have Another Chance For A Bullish Streak: Here’s How

3:44 am April 19, 2024

Getting in a position for synthetic common intelligence with examples

12:15 am April 19, 2024

Injective and Jambo companion to deliver mobile-based DeFi to tens of millions in rising markets

7:29 pm April 18, 2024

Successful Beta Service release of SOMESING, ‘My Hand-Carry Studio Karaoke App’