1 sessions
- Code talk300 - AdvancedIdentity and Access ManagementAmazon CognitoAmazon Verified PermissionsAWS Identity and Access Management (IAM)AWS LambdaTuesday, Jun 171:00 p.m. Tuesday, Jun 17This session focuses on transforming an existing application from role-based access control (RBAC) to policy-based access control (PBAC) using Amazon Verified Permissions (AVP) and Cedar policy. The drive for least privilege has led to role explosion in RBAC model and necessitates a shift towards PBAC, augmenting RBAC with attribute-based access control (ABAC). You will learn how to move authorization logic out of application code and implementing a centralized PBAC model. Attendees will also learn to define permissions as policies using Cedar and seamlessly migrate from RBAC to PBAC with minimal application logic changes, enabling more granular and scalable access control.Session Type: Code talkLevel: 300 - AdvancedTrack: Identity and Access Management