NEWFreshservice is now a Ploy integrationSee what shipped
INTEGRATIONSCLOUD INFRASTRUCTURE
Amazon Web Services28 OF 28 CAPABILITIES ASSESSED

Every AWS identity, role and resource, mapped to who holds it

Identity Center permission sets, IAM roles and the resources they reach, mapped per account with group membership granted from Ploy.

TYPE · INFRAAUTH · IAM ROLEDOMAIN · AWS.AMAZON.COM
Amazon Web Services connectorHOURLY SYNCCAPABILITIES
WHAT PLOY DOES
Sync IAM and Identity Center usersClassic IAM users and Identity Center SSO users both land as identities. Every user is reported active: the real enabled or disabled state is not read.
READ
Discover accounts, roles, permission sets and the resources behind themIAM roles, policies and groups, Identity Center groups and permission sets, the accounts themselves, and the EC2 instances, S3 buckets, RDS and DynamoDB databases, SQS queues and Lambda functions they reach.
READ
Map who can reach which account and resourceEvery entitlement resolves to the identity holding it and the level it grants, so a review can answer who could reach production.
READ
Create an Identity Center userPloy provisions the SSO user a joiner needs. Classic IAM users are not created.
WRITE
Grant and revoke group membershipIdentity Center and classic IAM group membership is added and removed from Ploy. Every write is gated on the integration write-access setting.
WRITE
2.1WHAT IT UNLOCKS

Three jobs this connector does on day one

ACCOUNTS AND ROLES

One map across every AWS account

IAM roles, policies and groups, Identity Center permission sets and the accounts they apply to all land in the graph, so access is read once rather than account by account.

PROVISIONING

Identity Center membership is the grant

An approved request creates the Identity Center user where one is needed and writes the group membership the permission set hangs off. Writes only run when the integration has write access turned on.

REVIEWS AND EVIDENCE

Who could reach production, answered

Reviews resolve every entitlement to the identity holding it and to the EC2 instance, S3 bucket, database, queue or function it reaches.

2.3

SETUP

TYPICALLY 10 MINUTES
STEP 01

Connect with least privilege

Grant Ploy a scoped, read-only role in Amazon Web Services to begin with.

STEP 02

Watch the first sync

Identities, roles and keys land in the graph.

STEP 03

Turn on writes

Choose which roles Ploy may grant and revoke, and who approves.

2.4OFTEN CONNECTED TOGETHER
OktaIDENTITY SOURCEGitHubSOURCE CONTROLSlackAPPROVALS
BROWSE ALL 62 INTEGRATIONS

Connect Amazon Web Services, see it in 10 minutes.