AWS IAM Roles Anywhere ~ IAM Risks Anywhere?
ID: 6bb8c35d-dca8-5827-acc1-111cdaf1b756
STIX ID: report--6bb8c35d-dca8-5827-acc1-111cdaf1b756
Feed Name: Zscaler Security Research Blog
**Executive summary:** This advisory explains AWS IAM Roles Anywhere — a feature enabling external workloads to assume AWS IAM roles using certificates issued by a trusted CA — details its operation (Trust Anchors, profiles, CN/OU condition keys), outlines security risks (compromised CA leading to account compromise, unenforced CN conditions, role reuse, and lack of source-IP-based controls), and recommends mitigations and best practices such as dedicated roles per workload, single-role-per-workload, grouping via profiles, and use of session policies to limit blast radius.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
