Before you begin
To complete this guide, you’ll need:- C1 Super Administrator role
- AWS with Identity Center configured
- Ability to set up an AWS role trust
Step 1: Integrate your AWS instance
Integrate your AWS instance with C1. Follow our instructions to set up the AWS v2 connector. Make sure to select these configuration options on the connector setup screen:- Enable support for AWS Organizations
- Enable support for AWS IAM Identity Center
Step 2: Configure AWS accounts for JIT access
Now that AWS is hooked up to C1, set AWS accounts as available for just-in-time access. To do this, we’ll configure entitlement management rules for each of the AWS accounts.1
Navigate to the Apps page, then select the “AWS” application that was created from Step 1.
2
In the Entitlement management section, click Edit next to Default config rules.
3
In the configuration rules pane, click the toggle to Enable configuration rules.
4
Select the account resource type.
5
In the Access profiles field, search for and select an access profile. For example, select Everyone to make the entitlements requestable by all users.
6
Finally, check the box at the bottom of the screen and click Apply.
Step 3: Request JIT access
Let’s go request AWS JIT access!1
In C1, click Requests and make sure that App catalog is selected.
2
Click AWS. A panel opens with the account resources available for you to request.
3
Click the account you want access to, then click Request on a specific entitlement (such as a permission set).
4
On the New request form that is shown, select the length of time you want access for.
5
Click Submit request.