Implementing Enterprise-managed IAM: An SRE Team’s Success Story

10:40 pm
October 24, 2023

Enterprise-managed identity and access management (IAM) systems provide cloud administrators with the ability to centrally configure access and security settings for an entire organization. In this case study, we explore how a site reliability engineering (SRE) team successfully implemented and managed their access across an enterprise.

Case Study

A large banking client has a centralized SRE team responsible for managing operations for all resources in the organization. To authenticate users to IBM Cloud enterprise accounts, the client uses federation. Additionally, all teams in the organization use Kubernetes and IBM Cloud Databases resources. The SRE team needs operational access to these resources across all teams and accounts.

Initially, manually managing access for the SRE team across a growing number of accounts was time-consuming and prone to errors. The access setup also did not meet certain audit controls, as child account administrators could update assigned access. To address these challenges, the client adopted enterprise-managed IAM templates.

By defining access for the SRE team using IAM templates and assigning them to the organization’s accounts, the client transformed the access management process from an ongoing effort to a one-time setup activity. This ensured that SRE access was automatically included in both existing and newly created accounts, and it could no longer be modified by child account administrators.

In this article, we will provide step-by-step instructions on how to implement a similar solution in your organization.

Prerequisites

  1. Be in the root enterprise account.
  2. The enterprise user performing this task should have the Template Administrator and Template Assignment Administrator roles on IAM services, as well as at least the Viewer role on the Enterprise service.
  3. Ensure that child accounts have enabled the enterprise-managed IAM setting.

Solution

To implement the enterprise-managed IAM solution for the SRE team, follow these steps:

  1. Create a trusted profile template.
  2. Add a trust relationship.
  3. Add access policy templates.
  4. Review and commit the trusted profile template.
  5. Assign the trusted profile template.

To update the template and assignment, follow these steps:

  1. Create a new template version.
  2. Add an additional access policy template.
  3. Review and commit the trusted profile template.
  4. Update the existing assignment to the new version.

Steps to create and assign a template

Follow the steps below to create and assign a trusted profile template for the SRE team:

  1. Go to Manage > Access (IAM). In the Enterprise section, click Templates > Trusted Profiles > Create. Create a trusted profile template for the SRE team.
  2. Add a trust relationship to dynamically add the SRE team to the trusted profile based on your Identity provider (IdP).
  3. Go to the Access tab to create access policies for the IBM Cloud Kubernetes Service and IBM Cloud Databases for MongoDB.
  4. Review and commit the trusted profile and policy templates to prevent changes.
  5. Assign the trusted profile template to the account group.

After completing the assignment, the SRE team members will have the necessary access to perform their duties in the accounts under the assigned group.

Conclusion

Implementing enterprise-managed IAM can significantly simplify access management for organizations. By using IAM templates and assigning them to accounts, the SRE team at the banking client was able to streamline access provisioning and ensure consistent access control across multiple accounts. This one-time setup activity saved time, reduced errors, and enhanced security.

FAQs

1. What is enterprise-managed IAM?

Enterprise-managed IAM enables cloud administrators to centrally configure access and security settings for their organization. It provides a streamlined approach to access management and ensures consistent control and security across accounts.

2. How does enterprise-managed IAM benefit SRE teams?

Enterprise-managed IAM simplifies access management for SRE teams by allowing them to define access through templates and assign them to relevant accounts. This eliminates the need for manual access setup and ensures that access control remains consistent and enforced.

3. Can the assigned access be updated by child account administrators?

No, with enterprise-managed IAM, the assigned access cannot be updated by child account administrators, ensuring that access control remains consistent and secure.


Share:

More in this category ...

7:27 pm April 30, 2024

Ripple companions with SBI Group and HashKey DX for XRPL answers in Japan

Featured image for “Ripple companions with SBI Group and HashKey DX for XRPL answers in Japan”
6:54 pm April 30, 2024

April sees $25M in exploits and scams, marking historic low ― Certik

Featured image for “April sees $25M in exploits and scams, marking historic low ― Certik”
5:21 pm April 30, 2024

MSTR, COIN, RIOT and different crypto shares down as Bitcoin dips

Featured image for “MSTR, COIN, RIOT and different crypto shares down as Bitcoin dips”
10:10 am April 30, 2024

EigenLayer publicizes token release and airdrop for the group

Featured image for “EigenLayer publicizes token release and airdrop for the group”
7:48 am April 30, 2024

VeloxCon 2024: Innovation in knowledge control

Featured image for “VeloxCon 2024: Innovation in knowledge control”
6:54 am April 30, 2024

Successful Beta Service release of SOMESING, ‘My Hand-Carry Studio Karaoke App’

Featured image for “Successful Beta Service release of SOMESING, ‘My Hand-Carry Studio Karaoke App’”
2:58 am April 30, 2024

Dogwifhat (WIF) large pump on Bybit after record reasons marketplace frenzy

Featured image for “Dogwifhat (WIF) large pump on Bybit after record reasons marketplace frenzy”
8:07 pm April 29, 2024

How fintech innovation is riding virtual transformation for communities around the globe  

Featured image for “How fintech innovation is riding virtual transformation for communities around the globe  ”
7:46 pm April 29, 2024

Wasabi Wallet developer bars U.S. customers amidst regulatory considerations

Featured image for “Wasabi Wallet developer bars U.S. customers amidst regulatory considerations”
6:56 pm April 29, 2024

Analyst Foresees Peak In Late 2025

Featured image for “Analyst Foresees Peak In Late 2025”
6:59 am April 29, 2024

Solo Bitcoin miner wins the three.125 BTC lottery, fixing legitimate block

Featured image for “Solo Bitcoin miner wins the three.125 BTC lottery, fixing legitimate block”
7:02 pm April 28, 2024

Ace Exchange Suspects Should Get 20-Year Prison Sentences: Prosecutors

Featured image for “Ace Exchange Suspects Should Get 20-Year Prison Sentences: Prosecutors”
7:04 am April 28, 2024

Google Cloud's Web3 portal release sparks debate in crypto trade

Featured image for “Google Cloud's Web3 portal release sparks debate in crypto trade”
7:08 pm April 27, 2024

Bitcoin Primed For $77,000 Surge

Featured image for “Bitcoin Primed For $77,000 Surge”
5:19 pm April 27, 2024

Bitbot’s twelfth presale level nears its finish after elevating $2.87 million

Featured image for “Bitbot’s twelfth presale level nears its finish after elevating $2.87 million”
10:07 am April 27, 2024

PANDA and MEW bullish momentum cool off: traders shift to new altcoin

Featured image for “PANDA and MEW bullish momentum cool off: traders shift to new altcoin”
9:51 am April 27, 2024

Commerce technique: Ecommerce is useless, lengthy are living ecommerce

Featured image for “Commerce technique: Ecommerce is useless, lengthy are living ecommerce”
7:06 am April 27, 2024

Republic First Bank closed by way of US regulators — crypto neighborhood reacts

Featured image for “Republic First Bank closed by way of US regulators — crypto neighborhood reacts”
2:55 am April 27, 2024

China’s former CBDC leader is beneath executive investigation

Featured image for “China’s former CBDC leader is beneath executive investigation”
10:13 pm April 26, 2024

Bigger isn’t all the time higher: How hybrid Computational Intelligence development permits smaller language fashions

Featured image for “Bigger isn’t all the time higher: How hybrid Computational Intelligence development permits smaller language fashions”
7:41 pm April 26, 2024

Pantera Capital buys extra Solana (SOL) from FTX

Featured image for “Pantera Capital buys extra Solana (SOL) from FTX”
7:08 pm April 26, 2024

Successful Beta Service release of SOMESING, ‘My Hand-Carry Studio Karaoke App’

Featured image for “Successful Beta Service release of SOMESING, ‘My Hand-Carry Studio Karaoke App’”
12:29 pm April 26, 2024

SEC sues Bitcoin miner Geosyn Mining for fraud; Bitbot presale nears $3M

Featured image for “SEC sues Bitcoin miner Geosyn Mining for fraud; Bitbot presale nears $3M”
10:34 am April 26, 2024

Business procedure reengineering (BPR) examples

Featured image for “Business procedure reengineering (BPR) examples”
7:10 am April 26, 2024

85% Of Altcoins In “Opportunity Zone,” Santiment Reveals

Featured image for “85% Of Altcoins In “Opportunity Zone,” Santiment Reveals”
5:17 am April 26, 2024

Sam Altman’s Worldcoin eyeing PayPal and OpenAI partnerships

Featured image for “Sam Altman’s Worldcoin eyeing PayPal and OpenAI partnerships”
10:55 pm April 25, 2024

Artificial Intelligence transforms the IT strengthen enjoy

Featured image for “Artificial Intelligence transforms the IT strengthen enjoy”
10:04 pm April 25, 2024

Franklin Templeton tokenizes $380M fund on Polygon and Stellar for P2P transfers

Featured image for “Franklin Templeton tokenizes $380M fund on Polygon and Stellar for P2P transfers”
7:13 pm April 25, 2024

Meta’s letting Xbox, Lenovo, and Asus construct new Quest metaverse {hardware}

Featured image for “Meta’s letting Xbox, Lenovo, and Asus construct new Quest metaverse {hardware}”
2:52 pm April 25, 2024

Shiba Inu (SHIB) unveils bold Shibarium plans as Kangamoon steals the display

Featured image for “Shiba Inu (SHIB) unveils bold Shibarium plans as Kangamoon steals the display”