Now we're going to create two roles. These roles will correspond to the groups we defined in Active Directory:
- AWSPowerUser: CanAssumePowerUser
- AWSReadOnly: CanAssumeReadOnly
- Start by creating the CanAssumePowerUser role first:
data:image/s3,"s3://crabby-images/8c15f/8c15fcb5fb3680e03412c15a73881221dbdc7114" alt=""
- We want this role to be an AWS Directory Service role, so be sure to select it before proceeding:
data:image/s3,"s3://crabby-images/cc798/cc798071b022b43908920d49cde248b1e6e290e8" alt=""
- Attach the AllowAssumeRole policy we have already created to this role:
Hint: You can filter the roles using the search box to make finding them easier.
data:image/s3,"s3://crabby-images/184cd/184cd21df0a5498a5c33aa87ad9c15f663a5f888" alt=""
- Click Create Role to confirm:
data:image/s3,"s3://crabby-images/8fe86/8fe869af8d6514f5d6554ea6e4d52a163e340346" alt=""
- Now go ahead and do exactly the same for the CanAssumeReadOnly role. Again, attach the AllowAssumeRole policy we created earlier:
data:image/s3,"s3://crabby-images/75dd6/75dd60c4451008790a18d2540abb0e8b06c79023" alt=""