Assign Groups From Trusted Domain to IAM Role Not Working

0

Hi

I have setup the AWS Directory Service and have a successful outgoing trust relationship to my on premise AD domain. I can assign permissions within my RDS instances, for example, and logon to them using my local, on premise, AD credentials
I'm now trying to get AWS Management Console access using our on premise AD credentials working
I've enabled Management Console access, created an IAM role with a trust relationship to AWS Directory - it shows up in the Delegate Console Access box within DS config
Problem - when I click on the IAM role and within Manage users and groups for this role I choose Add - all I see in the drop down is my AWS Directory Service AD domain, I can't see my on premise AD domain in order to select Groups from there
What am I doing wrong please ?

Thanks
STEVE

質問済み 4年前233ビュー
1回答
0

Found the problem. The trust relationship needs to be 2 way for Management Console access. I was using a one way, outbound trust

Just wish the documentation had been clearer on this point

回答済み 4年前

ログインしていません。 ログイン 回答を投稿する。

優れた回答とは、質問に明確に答え、建設的なフィードバックを提供し、質問者の専門分野におけるスキルの向上を促すものです。

質問に答えるためのガイドライン

関連するコンテンツ