One Identity Safeguard for Privileged Passwords can manage cloud platform accounts such as Amazon Web Services (AWS).

Before you add cloud platform accounts to SPP, you must first add an asset with which to associate the accounts. For more information, see Preparing Amazon Web Services platforms.

To add a cloud platform account

  1. Navigate to Asset Management > Assets.
  2. Click  New Asset from the toolbar.
  3. In the General tab:

    1. Name: Enter an asset name that is meaningful to you, such as "Cloud Account Server" which you can use to manage all cloud platform accounts.
    2. (Optional) Description: Enter a description for the asset.
  4. In the Connection tab:

    1. Platform: Select the appropriate product, such as Amazon Web Services.
    2. Version: For Amazon Web Services, select the version.
    3. Architecture: Enter the product's system architecture.
    4. Network Address: For Amazon Web Services, enter the AWS Account ID or Alias which can be found on the AWS IAM User's view.
    5. Authentication type: Select one of the following:
      1. Access Key to authenticate to the asset using an access key. Enter the following information:

        • Service Account Name: Enter the configured IAM service account.
        • Access Key ID: Enter the Access Key ID created for the IAM service account.
        • Secret Key: Enter the Secret Key created for the IAM service account.
      2. None to not authenticate to the asset and manually manage the asset.
  5. Click OK to save.

Once you add the cloud platform asset, you can associate accounts with it.

To add an account to the cloud platform

  1. In Assets, select the cloud platform asset and switch to the Accounts tab.
  2. Click  New Account from the details toolbar.
  3. In the Name field on the General tab, enter the cloud platform account username, email address, or phone number.
  4. (Optional) Enter a Description.
  5. On the Management tab, ensure the Enable Password Request option is checked.
  6. Click Browse to select a profile to govern this account.
  7. Click Add Account.
  8. Click OK to save.

Now you can manually check, change, or set the cloud platform account password; and, SPP can automatically manage the password according to the Check and Change settings in the profile governing the account.

To check out the cloud platform account

  1. Add a cloud platform Account Group and add the accounts to the group.
  2. Add an entitlement for the cloud platform accounts.
  3. Add users to the entitlements.
  4. Add a password release policy to the entitlement.
  5. Add the cloud platform Account Group to the scope of the policy.