July 2017
Intermediate to advanced
402 pages
9h 38m
English
At this point, users who are part of the AllUsers groups have enough permissions to manage their accounts. We can now restrict the permissions of users who don't have their accounts configured to use an MFA device or didn't refresh their sessions in a certain amount of time. To do that, we will add two new statements to the CommonIamPolicypolicy as follows:
from awacs.aws import (
Action,
Allow,
Condition,
NumericGreaterThan,
Deny,
Null,
Policy,
Statement,
)
Read now
Unlock full access