Assign Groups From Trusted Domain to IAM Role Not Working

0

Hi

I have setup the AWS Directory Service and have a successful outgoing trust relationship to my on premise AD domain. I can assign permissions within my RDS instances, for example, and logon to them using my local, on premise, AD credentials
I'm now trying to get AWS Management Console access using our on premise AD credentials working
I've enabled Management Console access, created an IAM role with a trust relationship to AWS Directory - it shows up in the Delegate Console Access box within DS config
Problem - when I click on the IAM role and within Manage users and groups for this role I choose Add - all I see in the drop down is my AWS Directory Service AD domain, I can't see my on premise AD domain in order to select Groups from there
What am I doing wrong please ?

Thanks
STEVE

질문됨 4년 전233회 조회
1개 답변
0

Found the problem. The trust relationship needs to be 2 way for Management Console access. I was using a one way, outbound trust

Just wish the documentation had been clearer on this point

답변함 4년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠