A SaaS provider's guide to securely integrating with customers' AWS accounts
ID: 0a7158ea-46fa-5b62-9e9e-c851ceb697eb
STIX ID: report--0a7158ea-46fa-5b62-9e9e-c851ceb697eb
Feed Name: Datadog Security Labs
This article provides an opinionated, defense-in-depth guide for SaaS vendors integrating with customers’ AWS accounts, emphasizing secure cross-account role assumptions with unique ExternalIds to prevent confused deputy attacks, least-privilege IAM policies (avoiding over-broad AWS managed policies), and automated, safe setup via CloudFormation/Terraform. It recommends guardrails such as rejecting roles without ExternalId enforcement, detecting overprivileged configurations, monitoring AssumeRole usage, leveraging session policies per microservice, using bastion and regional outbound roles, publishing dynamic IP ranges, and trusting a specific provider role rather than an entire account. The guidance aims to reduce provider liability and customer impact in the event of compromise while improving operational robustness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
