AWS IAM Identity Center ãå©ç¨ã㦠Azure AD ã®ã¦ã¼ã¶ã¼æ å ±ã§ AWS ã¢ã«ã¦ã³ãã¸ã®ã¢ã¯ã»ã¹ã試ãã¦ã¿ã Azure AD 㨠AWS IAM Identity Center ãé£æºããã¦ãAzure AD ã®èªè¨¼æ å ±ã§ AWS ã¢ã«ã¦ã³ãã«ã¢ã¯ã»ã¹ããè¨å®æ¹æ³ãã¾ã¨ãã¾ããã Azure AD ã¦ã¼ã¶ã¼ã®èªè¨¼æ å ±ã使ã£ã¦ AWS IAM Identity Center çµç±ã§ AWS ã¢ã«ã¦ã³ãã«ã¢ã¯ã»ã¹ããæ¹æ³ãç´¹ä»ãã¾ãã以åã«ãåæ§ã®ããã°ãæ¸ãã¾ããããAWS Single Sign-On æ代ã ã£ããããæ¹ãã¦æ¸ãç´ãã¾ãããæé ã«å¤ããããªãã確èªãããæå³ãããã¾ããããã»ã¼åãæé ã§è¨å®ã§ãã¾ããã æ§æã¨å ¨ä½ã®æµã æ§æå³ã¨è¨å®å 容ã示ãã¾ãã ã¦ã¼ã¶ã¼/ã°ã«ã¼ãæ å ±ã®åæ㯠SCIM ã«ããèªååæãæ¡ç¨ãã¦ãã¾ãã è¨å®ã®æµã SA
ãAWS SSOãAzureAD+AWSSSOã§ãå¼ç¤¾ã®AWSã¢ã«ã¦ã³ãã«ãããã¦ã¼ã¶ã¼ç®¡çãAzureADã«éç´ãã¤ã¤ãã¢ã¯ã»ã¹æ¨©éãã¢ã«ã¦ã³ã管çè å´ã§ç®¡çã§ããããã«ãã¦ã¿ãAWSSSOAzureADã¦ã¼ã¶ã¼ç®¡çAWSSSO ããã£ããã£ããã¼ãã ã¯ã©ã¦ãã¢ã¼ããã¯ãã£ãã¼ã ã®é½è¤ã§ãã AWSããå©ç¨ã®æ¹ã®ä¸ã§ããã«ãã¢ã«ã¦ã³ãéç¨ããã¦ããæ¹ã£ã¦ã©ããããããã£ãããã§ããããã ã¢ã«ã¦ã³ãä¸ã¤ãªãã¾ã ãããããã¤ãAWSã¢ã«ã¦ã³ãããã£ã¦åå¥ã«IAMã¦ã¼ã¶ã¼çºè¡ã¨ããã¦ãã¨éè·è ã¢ã«ã¦ã³ãã®åé¤å¿ãã¨ããã£ãããè²ã é¢åã§ãããã ãï¼ããããªãã£ã¦ï¼ ã»ãããããã½ã¼ã¹ã³ã¼ãã®ããããªã¨ããã«åããããªå¦çãã³ããããããã§ãä¿®æ£å ããã¨ãã«å ¨é¨æä½æ¥ã§ç´ããªãã¨ãããªãããã©ããããæãåºãã¦ãã ããã ããã©ãã§ããï¼ åããããªå¦çã¯ä¸ãæã«ã¾ã¨ãã¦ä½¿ãã¾ãããã»ãã
ã¨ã³ã¿ã¼ãã©ã¤ãºã¯ã©ã¦ãé¨ã®æ¾ç°ã§ããããã«ã¡ã¯ã ã¿ã¤ãã«é·ãã§ããçãããã®ã¯è«¦ãã¾ããã Cloud Identityï¼Google Workspaceã®IdPæ©è½ã ããæãåºãããããªãã®ãç¡åã§ä½¿ãã¾ããï¼ã¨AWS IAM Identity Centerï¼æ§: AWS Single Sign-Onï¼ã使ã£ãã·ã³ã°ã«ãµã¤ã³ãªã³ã®ã»ããã¢ãããè¡ãæ©ä¼ãããã¾ããã®ã§ããã°ã«ã¾ã¨ãã¦ã¿ã¾ããåãã¦è§¦ãããµã¼ãã¹ã§ããã®ã§ï¼ããããã·ã³ã°ã«ãµã¤ã³ãªã³èªä½é¦´æã¿ãããã¾ããã§ãããï¼ãããããã®ãµã¼ãã¹æ¦è¦ã«ã¤ãã¦ãæãä¸ãã¦ããã¾ãã AWS IAM Identity Centerã¨ã¯ ä½ãã§ããã®ã å¤é¨IdPé£æºãã¿ã¼ã³ããã£ãã説æ Cloud Identityï¼Google Workspace代æ¿ï¼ã¨ã®é£æº ä½æ¥ã®æµã 1. ãã¡ã¤ã³åå¾ 2. Cloud Identityã®ç»
Azure AD ã®ã¨ã³ã¿ã¼ãã©ã¤ãºã¢ããªã±ã¼ã·ã§ã³ã« AWS SSO ã¨é£æºããããã®ã®ã£ã©ãªã¼ã追å ããã¦ãããããAzure AD ã®ã¦ã¼ã¶æ å ±ãç¨ã㦠AWS ããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã«ãµã¤ã³ã¤ã³ããç°å¢ã®æ§ç¯ã試ãã¦ã¿ã¾ããã Azure AD ã®ã¦ã¼ã¶æ å ±ãç¨ã㦠AWS ããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã«ãµã¤ã³ã¤ã³ããæ¹æ³ã¯ããã¤ãããã¾ãããæ¬ããã°ã§ã¯ AWS SSO ãç¨ã㦠AWS ã¢ã«ã¦ã³ãã¸ã®ã¢ã¯ã»ã¹æ¨©ã管çãã¦ããç°å¢ã«ããã¦ãAWS SSO 㨠Azure AD ã SAML ã«ããé£æºããæ¹æ³ãç´¹ä»ãã¾ãã 2023.3.21 è¿½è¨ AWS IAM Identity Center çãæ°ããæ¸ãã¾ããã æ§æã¨å ¨ä½ã®æµã è¨å®ããæ§æã¨ä½æ¥ã®æµãã示ãã¾ãã ã¦ã¼ã¶/ã°ã«ã¼ãã®å±æ§æ å ±ã®åæ㯠SCIM ã«ããèªååæãæ¡ç¨ãã¦ãã¾ãã æ§æå³ å ¨ä½ã®æµã SAML ã®
AWS Security Blog Getting started with AWS IAM Identity Center delegated administration September 12, 2022: This blog post has been updated to reflect the new name of AWS Single Sign-On (SSO) â AWS IAM Identity Center. Read more about the name change here. Recently, AWS launched the ability to delegate administration of AWS IAM Identity Center (AWS IAM Identity Center) in your AWS Organizations or
翻訳ã¯æ©æ¢°ç¿»è¨³ã«ããæä¾ããã¦ãã¾ããæä¾ããã翻訳å 容ã¨è±èªçã®éã§é½é½¬ãä¸ä¸è´ã¾ãã¯çç¾ãããå ´åãè±èªçãåªå ãã¾ãã ã使ç¨ãã IAM Identity Center èªè¨¼ã®è¨å® AWS CLI ãã®ãããã¯ã§ã¯ã AWS IAM Identity Center ï¼IAM Identity Center) AWS CLI ã使ç¨ã㦠ãè¨å®ãã¦ã AWS CLI ã³ãã³ããå®è¡ããããã®èªè¨¼æ å ±ãåå¾ããæ¹æ³ã«ã¤ãã¦èª¬æãã¾ããIAM Identity Center ã§ã¦ã¼ã¶ã¼ãèªè¨¼ãã¦ã config ãã¡ã¤ã«ãä»ã㦠AWS CLI ã³ãã³ããå®è¡ããããã®èªè¨¼æ å ±ãåå¾ããæ¹æ³ã¯ä¸»ã« 2 ã¤ããã¾ãã
ã¯ããã« ããã«ã¡ã¯ã大éªãªãã£ã¹ã®æã§ãã AWS SSOã®ç®¡çãã¡ã³ãã¼ã¢ã«ã¦ã³ãã«å§ä»»ã§ããããã«ãªãã¾ããã®ã§æ©éãã£ã¦ããããã¨æãã¾ãã ãã¾ã¾ã§ ãããã ä½ãããããã 管çã¢ã«ã¦ã³ãã¯ã管çã¢ã«ã¦ã³ãã§ããã§ããªãã¿ã¹ã¯ã®ã¿ã«éå®ãã¦ãããã¨ã管çã¢ã«ã¦ã³ãã®ãã¹ããã©ã¯ãã£ã¹ã¨ããã¦ãã¾ãã ä»åã®ã¢ãããã¼ããæ´»ç¨ãããã¨ã§ãæ¨å¥¨ãããAWSã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ã«ä¸æ©è¿ã¥ããã¨ãåºæ¥ã¾ãã ãã£ã¦ã¿ã AWS SSOã®ããã·ã¥ãã¼ããããè¨å®ã-ã管çã-ãã¢ã«ã¦ã³ããç»é²ããé¸æãã¾ãã å§ä»»å ã®ã¡ã³ãã¼ã¢ã«ã¦ã³ããé¸æããã¢ã«ã¦ã³ããç»é²ããé¸æãã¾ãã æ£å¸¸ã«ç»é²ã§ãããã¨ã確èªãã¾ãã åä½ç¢ºèª å§ä»»å ã®ã¡ã³ãã¼ã¢ã«ã¦ã³ãã«ãã°ã¤ã³ãAWS SSOã®ããã·ã¥ãã¼ããè¦ã¦ã¿ãã¨ã¦ã¼ã¶ã¼ã®ä¸è¦§ãåç §ã§ããããã«ãªã£ã¦ãã¾ãã ã¦ã¼ã¶ã¼ã®ä½æãã¢ããã³ã§
AWS Single Sign-On (AWS SSO) ããçµç¹å ã®ãã¹ã¦ã®ã¡ã³ãã¼ã¢ã«ã¦ã³ãã«å¯¾ãã¦ãAWS Organizations å§ä»»ç®¡çè ã¢ã«ã¦ã³ãããã®éä¸ç®¡ç㨠API ã¢ã¯ã»ã¹ããµãã¼ãããããã«ãªãã¾ãããã¤ã¾ãããã¹ã¦ã®ã¡ã³ãã¼ã¢ã«ã¦ã³ããä¸å 管çããããã«ä½¿ç¨ã§ããçµç¹å ã®ã¢ã«ã¦ã³ããæå®ã§ãããã¨ã«ãªãã¾ããå§ä»»ããã管çã使ç¨ããã¨ã管çã¢ã«ã¦ã³ãã使ç¨ããå¿ è¦æ§ãæ¸ãããã¨ã§ããã¹ããã©ã¯ãã£ã¹ã«å¾ããã¨ãã§ãã¾ãã AWS SSO ã¨ã¯ãAWS ä¸ã§ã¯ã¼ã¯ãã©ã¼ã¹ã¢ã¤ãã³ãã£ãã£ãä½æãã¾ãã¯æ¥ç¶ããAWS çµç¹å ¨ä½ã®ã¢ã¯ã»ã¹ãä¸å çã«ç®¡çãããã®ã§ãã管çã¢ã«ã¦ã³ã㧠AWS SSO ãæå¹ã«ããã¨ãAWS SSO ã³ã³ã½ã¼ã«ããã¡ã³ãã¼ã¢ã«ã¦ã³ããæå®ã§ãã¾ãã管çè ã¯ãå§ä»»ãããã¡ã³ãã¼ã¢ã«ã¦ã³ãã«ãµã¤ã³ã¤ã³ãã¦ãã¦ã¼ã¶ã¼ã¨ã°ã«ã¼ããã¢ããªã±ã¼ã·ã§ã³
æ¬è¨äºã¯ ããæ¨ãï½AWSã¢ã¯ã¼ãã¨ã³ã¸ãã¢ç·¨ï½ 1æ¥ç®ã®è¨äºã§ãã ð» ã¤ãã³ãåç¥ â¶â¶Â æ¬è¨äºÂ â¶â¶ 2æ¥ç® ð» ããã«ã¡ã¯ãä¸éã§ãã NRIãããã³ã ã2022 Japan APN Ambassadors / Top Engineers / ALL Certificate Engineers ã«ããæ¨ããã¯ã·ãªã¼ãºã§ãã ç§ãç´¹ä»ããã®ã¯AWS Single Sign-On (AWS SSO)ã§ããæé«ã®ãµã¼ãã¹ã§ãã AWS SSOã®æ¦è¦ AWS SSOãæå¹ã«ããã¨ãä¸å 管çãããï¼ä¸ã¤ã®ï¼ã¦ã¼ã¶ã¼å/ãã¹ã¯ã¼ãã§ãã°ã¤ã³ãããã¨ã«ãããè¤æ°ã®AWSã¢ã«ã¦ã³ãã¸ãã°ã¤ã³ã§ããããã«ãªãã¾ãã âã¯ãã°ã¤ã³ç»é¢ã§ãã ãã°ã¤ã³ããã¨ã»ã»æ¨©éãããAWSã¢ã«ã¦ã³ããä¸è¦§ã§è¡¨ç¤ºãããåAWSã¢ã«ã¦ã³ãã¸ãã°ã¤ã³ã§ãã¾ãã 便å©ã§ããã AWS SSOã®ä»çµã¿ AWS SSOã§é
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}