AWS Partner Network (APN) Blog
Tag: AWS IAM
Improve the Availability of Existing Okta IAM Federation Setup Using Multi-Region SAML Endpoints
Federation using SAML 2.0 enables customers to use their existing external IdP and avoid managing multiple sources of identities when accessing AWS accounts. This post builds on the recommendation of using regional SAML endpoints for failover by showing how you can configure Okta‘s federation with IAM to increase its availability. Learn how to configure Okta, an AWS Security Competency Partner, to utilize multiple regional AWS SAML sign-in endpoints that can be deployed at setup by the Okta admin.
Accelerating DevOps Transformations Using LTI’s Infinity DevOps
Being digital requires DevOps at scale to rapidly adopt new technologies, transform legacy applications, innovate faster, and respond swiftly to ever-changing customer needs. Learn how DevOps can be implemented via tools like LTI’s Infinity DevOps, a self-service, scalable DevOps platform designed to provide faster, stable, and continuous deliveries to create leaner automated processes and accelerate delivery and productivity.
Automate the Enrollment of EC2 Mac Instances into Jamf Pro
Since the release of Amazon EC2 Mac instances, AWS customers have been able to access on-demand Apple Mac devices in the AWS Cloud. In collaboration with Jamf, an AWS Partner and leader in Apple device management, AWS has developed integration between the Amazon EC2 Mac instances and Jamf Pro to simplify managing, securing, and configuring EC2 Mac instances. Learn how to configure AWS and Jamf accounts to automatically enroll EC2 Mac into Jamf Pro EC2 Mac instances when they are launched.
Amazon EBS Direct APIs Enable Infrastructure-Less and Agent-Less Data Protection with Clumio
AWS and its backup partners continue to innovate to meet customer needs, and one example is the Amazon EBS direct APIs. Learn more about these APIs and how they transformed the Clumio solution. This post discusses issues the EBS direct APIs were created to solve and how Clumio used them to improve its cloud backup solution. We’ll show how Clumio and the EBS direct APIs work together to provide a powerful solution to solve customer data protection challenges.
Archive, Manage, and Leverage SAP Documents on AWS with Syntax CxLink Documents
SAP systems need a capable document management solution. Syntax, an SAP Gold Partner and AWS Premier Tier Services Partner, has focused on customer needs to develop a cloud-native, SAP-certified solution to meet data and document modernization requirements through its CxLink product portfolio. Explore the Syntax CxLink Documents solution and the process of how to handle a large number of documents from SAP applications and storing them directly on Amazon S3.
Storing Multi-Tenant SaaS Data with Amazon OpenSearch Service
Amazon OpenSearch Service is frequently used by SaaS providers to address a broad range of use cases. The use of Amazon OpenSearch Service in a multi-tenant environment, however, introduces a collection of new considerations that will influence how you partition, isolate, deploy, and manage your solution. Explore the strategies and patterns that are used to address these common issues, and look at the specific models used to represent and isolate each tenant’s data with Amazon OpenSearch Service constructs.
Securely Using External ID for Accessing AWS Accounts Owned by Others
It’s often required for a partner solution running on Amazon Web Services to access AWS accounts owned by their customers (third-party AWS accounts). This kind of access is known as cross-account access. In such scenarios, a cross-account AWS Identity and Access Management (IAM) role with external ID should be used. Explore the best practices for using external ID to avoid the confused deputy problem it is designed to solve.
Active Directory Authentication and Authorization with Amazon RDS
Learn how to set up Active Directory authentication with authorization for Postgres. Heimdall Data provides synchronization scripts for other databases as well, allowing all Amazon RDS instance types to be supported in a similar way. Using Active Directory authentication allows organizations to standardize their password and authorization management via a globally available authentication store, reducing management overhead and improving security and auditing capabilities.
Self-Service Platform for Standardized Amazon EKS Deployments Across the Organization
AWS provides a secure, reliable, and scalable environment for customers to run their container workloads. Customers running containers on premises are looking to move to AWS to gain agility benefits and reduce technical debt of managing their own infrastructure. Learn how Tech Mahindra transitioned a customer from an on-premises self-managed Kubernetes environment to a managed Amazon EKS platform with centralized self-service deployment options using AWS Service Catalog.
Designing a Multi-Tenant SFTP Server with AWS Transfer Family
Data security is a particularly important topic for multi-tenant SaaS applications that handle customers’ sensitive data. How to securely segregate tenant data and how to provide data access to customers will vary depending on the SaaS solution’s architecture and its requirements. This post explores how SaaS vendors can build secure, scalable, and cost-effective data exchange mechanisms using SFTP (SSH File Transfer Protocol) with AWS managed services like AWS Transfer Family.





