Author: Keith Stafford


  • Security controls for your AWS Management Account

    In this post, we discuss a recent change from AWS which allows for updating the root user email address for any member account that are attached to an AWS Organization. Along with the associated security considerations of that change. What’s new?AWS recently announced the ability to centrally manage the root email addresses of member accounts…

  • Approaches for recovering Root Account access.

    In this post, we discuss options for regaining access to an AWS root account, even in the face of numerous challenges! Bob Left the Company on Bad TermsIt happens. One day, the company’s cloud guru exits the company, voluntarily or involuntarily, for new pastures. Bridges are burned, communication channels are severed, and LinkedIn connections are…

  • Simplifying Access Management: An Introduction to AWS IAM Identity Center

    In this post we discuss AWS IAM Identity Center, a powerful service designed to streamline Single Sign-On (SSO) across AWS accounts and applications. What is AWS IAM Identity Center?AWS IAM Identity Center, formerly known as AWS Single Sign-On (SSO), is a cloud service from Amazon Web Services that simplifies the management of SSO access and…

  • Empowering Your AWS Environment with Service Control Policies

    Welcome! Today, we’re diving into AWS Service Control Policies (SCPs)! Whether you’re a seasoned AWS user or just getting started, understanding SCPs can elevate your control and governance to new heights. What are AWS Service Control Policies?AWS Service Control Policies (SCPs) are a type of policy that you can use with AWS Organizations to manage…

  • Mastering AWS Multi-Account Management

    A common question I receive from customers is how to effectively manage a multi-account AWS structure as their companies grow. It’s an excellent topic because effective management of AWS environments is crucial for organizations aiming to optimize security, compliance, and resource utilization. AWS’s multi-account architecture offers a comprehensive approach to partitioning workloads, bolstering security, and…