Why can I choose to enable or disable each region endpoint in AWS STS?

Asked 2 years ago, Updated 2 years ago, 129 views

Why can I enable/disable each region endpoint in STS?
What are the security threats when enabled recklessly?

Enter a description of the image here

aws aws-iam

2022-09-30 20:21

1 Answers

Why?

It's about the design concept of the service, so please ask AWS directly.

Disabling unused regions has the advantage of limiting unnecessary access to unused regions.
However, I personally think that it is sufficient in many cases to tie it properly according to the IAM policy, even if you don't tie it there.


2022-09-30 20:21

If you have any answers or tips


© 2024 OneMinuteCode. All rights reserved.