A. Create IAM policies that include the required permissions. Include the aws PrincipalTag condition key.
B. Create permission sets. Attach an inline policy that includes the required permissions and uses the aws:PrincipalTag condition key to scope the permissions. Most Voted
C. Create a group in the IdP. Place users in the group. Assign the group to accounts and the permission sets in AWS SSO. Most Voted
D. Create a group in the IdP. Place users in the group. Assign the group to OUs and IAM policies.
E. Enable attributes for access control in AWS SSO. Apply tags to users. Map the tags as key-value pairs.
F. Enable attributes for access control in AWS SSO. Map attributes from the IdP as key-value pairs. Most Voted

- Awsexamhub website is not related to, affiliated with, endorsed or authorized by Amazon.
- Trademarks, certification & product names are used for reference only and belong to Amazon.