Assign Groups From Trusted Domain to IAM Role Not Working

0

Hi

I have setup the AWS Directory Service and have a successful outgoing trust relationship to my on premise AD domain. I can assign permissions within my RDS instances, for example, and logon to them using my local, on premise, AD credentials
I'm now trying to get AWS Management Console access using our on premise AD credentials working
I've enabled Management Console access, created an IAM role with a trust relationship to AWS Directory - it shows up in the Delegate Console Access box within DS config
Problem - when I click on the IAM role and within Manage users and groups for this role I choose Add - all I see in the drop down is my AWS Directory Service AD domain, I can't see my on premise AD domain in order to select Groups from there
What am I doing wrong please ?

Thanks
STEVE

已提問 4 年前檢視次數 233 次
1 個回答
0

Found the problem. The trust relationship needs to be 2 way for Management Console access. I was using a one way, outbound trust

Just wish the documentation had been clearer on this point

已回答 4 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南