AWS Organizations縺ィ縺ッシ櫑AM縺ィ縺ョ髢「菫ゅr縺励▲縺九j逅隗」縺吶k
Solutions Architect - Professional繧貞叙蠕励@縺ヲ縺九iAWS縺ョ繝吶シ繧キ繝繧ッ縺ェ驛ィ蛻繧定ァヲ繧区ゥ滉シ壹′貂帙▲縺ヲ縺励∪縺」縺溘ョ縺ァ縲∵隼繧√※遏・隴倥r謨エ逅縺吶k縺溘a縺ォ險倅コ九↓縺セ縺ィ繧√∪縺励◆縲
莉翫∪縺ァ縲守炊隗」縺励※縺繧九h縺縺ァ繧医¥繧上°縺」縺ヲ縺縺ェ縺九▲縺溘衆rganizations蜻ィ繧翫r縲守炊隗」縺ァ縺阪◆シ√上→諤昴∴繧九h縺縺ォ縺ェ繧九→諤昴>縺セ縺吶
蜈ィ菴捺ヲりヲ∝峙
AWS Organizations 縺ィ 蜷遞ョIAM 縺ィ縺ョ髢「菫よァ繧呈紛逅縺励◆蝗ウ縺後%縺。繧峨↓縺ェ繧翫∪縺吶
邏ー縺九¥譖ク縺榊コ縺吶→譖ク縺阪″繧後↑縺縺ァ縺吶′讎りヲ√r逅隗」縺吶k荳翫〒縺ッ縺薙ョ蜀螳ケ縺ァ蜊∝縺ァ縺吶

縺セ縺壹^rganizations 縺ィ縺ッ隍謨ー縺ョAWS繧「繧ォ繧ヲ繝ウ繝医r邨ア蜷育ョ。逅縺吶k縺溘a縺ョ繧オ繝シ繝薙せ縺ァ縺吶
蝗ウ縺ョ蜿ウ蛛エ縺ォ險倩シ峨ョ騾壹jAWS繧「繧ォ繧ヲ繝ウ繝医#縺ィ縺ォIAM繝ヲ繝シ繧カ繧ЕC2縺ェ縺ゥ縺ョ繝ェ繧ス繝シ繧ケ繧呈戟縺」縺ヲ縺縺セ縺吶′縲^rganizations 繧剃スソ縺莠九〒縲窟WS繧「繧ォ繧ヲ繝ウ繝医◎縺ョ繧ゅョ縺ォ蟇セ縺励※讓ゥ髯舌r蛻カ髯舌阪瑚ォ区アゅr荳蜈蛹悶阪〒縺阪k繝。繝ェ繝繝医′縺ゅj縺セ縺吶

Organizations縺ォ縺ッ1縺、縺ョ邂。逅繧「繧ォ繧ヲ繝ウ繝医→隍謨ー縺ョ繝。繝ウ繝舌シ繧「繧ォ繧ヲ繝ウ繝医r謖√▽縺薙→縺後〒縺阪∪縺吶
縺薙ョ繧ュ繝」繝励メ繝」縺ァ縺ッsyun03縺後檎ョ。逅繧「繧ォ繧ヲ繝ウ繝医阪[ember縺後後Γ繝ウ繝舌シ繧「繧ォ繧ヲ繝ウ繝医阪〒縺吶
繧ゅ■繧阪s縺昴l縺槭l縺窟WS繧「繧ォ繧ヲ繝ウ繝医↓邏蝉サ倥>縺ヲ縺縺セ縺吶ョ縺ァ縲√◎繧後◇繧檎腸蠅繧繝ェ繧ス繝シ繧ケ繧呈戟縺」縺ヲ縺縺セ縺吶
繝。繝ウ繝舌シ繧「繧ォ繧ヲ繝ウ繝医°繧碓rganizations 繧呈桃菴懊☆繧九%縺ィ縺ッ縺ァ縺阪∪縺帙s縲
蜷鬆逶ョ縺ョ隱ャ譏
逋サ蝣エ縺吶k繝昴う繝ウ繝医ッシ吶▽縺ァ縺吶
- 邨郢
- 邨郢泌腰菴(OU)
- 邂。逅繧「繧ォ繧ヲ繝ウ繝
- 繝。繝ウ繝舌シ繧「繧ォ繧ヲ繝ウ繝
- AWS繧「繧ォ繧ヲ繝ウ繝
- IAM繝ヲ繝シ繧カ
- IAM繝昴Μ繧キ繝シ
- IAM繝ュ繝シ繝ォ
- SCP
縺。縺ェ縺ソ縺ォ縲栗AM繧「繧ォ繧ヲ繝ウ繝医阪窟WS繝ヲ繝シ繧カ縲阪→縺縺蜊倩ェ槭ッ蟄伜惠縺励∪縺帙s縲AWS繧貞ュヲ繧薙〒縺縺丈ク翫〒縺薙ョ繧医≧縺ェ騾隱槭′縺ゅk縺ィ豺キ荵ア繝昴う繝ウ繝医↓縺ェ繧翫∪縺吶h縺ュ縲
縺昴l縺ァ縺ッ蜷繝昴う繝ウ繝医↓縺、縺縺ヲ隗」隱ャ縺励※縺縺阪∪縺吶
邨郢
AWS繧「繧ォ繧ヲ繝ウ繝医r邨ア蜷医@縺ヲ邂。逅縺吶k縺溘a縺ョ邂。逅蜊倅ス阪〒縺吶AWS Organizations 繧ウ繝ウ繧ス繝シ繝ォ繧剃スソ逕ィ縺励※縲∫オ郢泌縺ョ縺吶∋縺ヲ縺ョ繧「繧ォ繧ヲ繝ウ繝医r荳蜈逧縺ォ陦ィ遉コ縺翫h縺ウ邂。逅縺ァ縺阪∪縺吶らオ郢斐↓縺ッ縲1 縺、縺ョ邂。逅繧「繧ォ繧ヲ繝ウ繝医→縲√ぞ繝ュ莉・荳翫ョ繝。繝ウ繝舌シ繧「繧ォ繧ヲ繝ウ繝医r蜷ォ縺ソ縺セ縺吶
繧ウ繝ウ繧ス繝ェ繝薙Η繝シ繝繝繝峨ン繝ェ繝ウ繧ー縺ォ繧医j隲区アゅr縺セ縺ィ繧√k縺薙→縺悟庄閭ス縺ァ縺吶
邨郢泌腰菴搾シOUシ
邨郢泌縺ォ螳夂セゥ縺吶k荳倶ス阪ョ邨郢斐〒縺吶らオ郢泌腰菴阪r繝阪せ繝医☆繧九%縺ィ繧ょ庄閭ス縺ァ縺吶
邂。逅繧「繧ォ繧ヲ繝ウ繝
邂。逅繧「繧ォ繧ヲ繝ウ繝医↓縺ッ縲∵髪謇輔>繧「繧ォ繧ヲ繝ウ繝医□縺代〒縺ェ縺上√Γ繝ウ繝舌シ繧「繧ォ繧ヲ繝ウ繝医↓繧医▲縺ヲ逋コ逕溘@縺溘☆縺ケ縺ヲ縺ョ譁咎代r謾ッ謇輔≧雋ャ莉サ縺後≠繧翫∪縺吶らオ郢斐ョ邂。逅繧「繧ォ繧ヲ繝ウ繝医r螟画峩縺吶k縺薙→縺ッ縺ァ縺阪∪縺帙s縲
繝。繝ウ繝舌シ繧「繧ォ繧ヲ繝ウ繝
邨郢斐↓諡帛セ縺輔l繧九°邨郢斐ョ荳ュ縺ァ菴懈舌&繧後◆AWS繧「繧ォ繧ヲ繝ウ繝医〒縺吶ゅΓ繝ウ繝舌シ繧「繧ォ繧ヲ繝ウ繝医ッ蟄伜惠縺吶k縺薙→縺後〒縺阪∪縺吶
繝。繝ウ繝舌シ繧「繧ォ繧ヲ繝ウ繝医ッOU縺ョ荳ュ縺ォ謇螻槭☆繧九%縺ィ繧Soot逶エ荳九↓謇螻槭☆繧九%縺ィ繧ゅ〒縺阪∪縺吶
TIPS
邨郢泌縺ァ縺ョ繝ェ繧ス繝シ繧ケ蜈ア譛峨r譛牙柑縺ォ縺吶k縺ォ縺ッ
AWS Resource Access Manager 繧剃スソ縺縺セ縺吶
AWS RAM 繧ウ繝ウ繧ス繝シ繝ォ縺ョ Settings 繝壹シ繧ク繧帝幕縺阪∪縺吶
Enable sharing with AWS Organizations 繧帝∈謚槭@縺ヲ縺九i Save settings 繧帝∈謚槭@縺セ縺吶
https://docs.aws.amazon.com/ja_jp/ram/latest/userguide/getting-started-sharing.html

驛ィ鄂イ縺斐→縺ォ繝ェ繧ス繝シ繧ケ蛻ゥ逕ィ譁吶ョ隲区アょ縺代k
繧ウ繧ケ繝磯榊繧ソ繧ー繧貞茜逕ィ縺励※OU縺斐→縺ォ隲区アゅr蛻縺代k蠢隕√′縺ゅj縺セ縺吶
OU縺斐→縺ォ雋サ逕ィ繧貞縺代k讖溯ス縺ッ縺斐*縺縺セ縺帙s縲
繝。繝ウ繝舌シ繧「繧ォ繧ヲ繝ウ繝医r蜑企勁縺吶k縺ォ縺ッ
繝。繝ウ繝舌シ繧「繧ォ繧ヲ繝ウ繝医r邨郢斐°繧蛾勁螟悶☆繧九◆繧√↓縺ッ縲√せ繧ソ繝ウ繝峨い繝ュ繝ウ繧「繧ォ繧ヲ繝ウ繝医〒縺ゅk蠢隕√≠繧願ォ区アよュ蝣ア縺檎匳骭イ縺輔l縺ヲ縺繧九↑縺ゥ縺ョ譚。莉カ縺後≠繧翫∪縺吶
https://docs.aws.amazon.com/ja_jp/organizations/latest/userguide/orgs_manage_account-before-remove.html
AWS繧「繧ォ繧ヲ繝ウ繝医#縺ィ縺ォIAM繝ヲ繝シ繧カ繧剃ス懈舌@縺ェ縺上※繧ゅ>縺
髢狗匱迺ー蠅縺ョIAM繝ヲ繝シ繧カ縺九i譛ャ逡ェ迺ー蠅繧呈桃菴懊@縺溘>蝣エ蜷医ッassume role縺ォ繧医j譛ャ逡ェ迺ー蠅逕ィ縺ョIAM繝ヲ繝シ繧カ縺ォ譏譬シ縺励※驕狗畑縺励∪縺吶
縺薙ョ閠縺域婿縺窟WS縺ォ縺翫¢繧九槭Ν繝√い繧ォ繧ヲ繝ウ繝域姶逡・縺ョ蝓コ譛ャ縺ァ縺吶
譛ャ逡ェ迺ー蠅縺ク縺ョ繧「繧ッ繧サ繧ケ繧棚P繧「繝峨Ξ繧ケ縺ァ蛻カ髯舌@縺溘>
譛ャ逡ェ迺ー蠅縺ェ縺ゥ縺ァIP蛻カ髯舌′蠢隕√↑蝣エ蜷医↓縺ッ縲‖ssume role縺輔l繧九ョIAM縺ォIAM繝昴Μ繧キ繝シ繧定ィュ螳壹☆繧句ス「縺ァ蛻カ髯舌r陦後>縺セ縺吶
譛ャ逡ェ逕ィ縺ョIAM繝昴Μ繧キ繝シ縺ォ荳玖ィ倥ョ騾壹j險倩ソー縺吶k縲
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::xxxxxxxxxxxx:user/Operator"
},
"Action": "sts:AssumeRole"
},
{
"Effect": "Deny",
"Principal": {
"AWS": "arn:aws:iam::xxxxxxxxxxxx:user/Operator"
},
"Action": "sts:AssumeRole",
"Condition": {
"NotIpAddress": {
"aws:SourceIp": "xxx.xxx.xxx.xxx/32"
}
}
}
]
}


