In this step either Security or Cloud Administrators will onboard a limited set of initial builders who will have access to their team development environments. The outcome is that a small team of builders has the knowledge to start using their team development AWS accounts, where to find basic usage documentation, and who to contact for support.
This step should take about 60 minutes to complete.
Work with your cross-functional colleagues in Security, Compliance, and Finance to assemble the basic form of a getting started document and share it with the members of the initial builder teams so that they understand the fundamentals of their responsibilities, access permissions, and how to access and begin using their team development AWS accounts.
See the Example Getting Started Guide for Builder Team Members as a recommended starting point.
Create a new group in AWS SSO for each of the builder teams and associate those groups with an initial set of permissions and their respective team development AWS accounts.
master account.Management console associated with the AWSAdministratorAccess role.AWS SSO.Groups in AWS SSO.Create group.example with your organization’s identifier:example-team-a-devexample-foundation-devTeam A developmentFoundation team developmentCreate.AWS accounts in AWS SSO.Team A - DevFoundation - DevAssgn users.Groups.example-team-a-devexample-foundation-devNext: Permission sets.example-base-dev-team.Finish.Repeat the process above to create a group for your foundation team and enable this group to access their team development AWS account.
Now that you’ve established the two team development oriented groups in AWS SSO and wired these groups to a set of permissions and AWS accounts, your next step is to create a user in AWS SSO for each builder team member.
Typically, the user name will simply be the user’s corporate email address that is often used for SaaS services.
Next, access the AWS SSO service to begin adding an AWS SSO user for each foundation team member:
Users in AWS SSO.Add user.Next: Groups.example-team-a-dev or similar.Add user.Since you’ve already created users in AWS SSO for foundation team members, all you need to do to at this stage is to add the foundation team member users to the newly created foundation team development group in AWS SSO.
Groups in AWS SSO.example-foundation-dev.Add users.Add users.The foundation team members now have access to the foundation team development AWS account.
Meet with the builder team members to brief them on their access and other topics covered in the Example Getting Started Guide for Builder Team Members.