No project description provided
Project description
AWS IDC List User Permissions
List all users and their corresponding permission set within an AWS Identity Center instance. AWS Identity Center is the new name for AWS SSO.
Will iterate through all users, and determine their permission sets (either directly attached to the user, or via a Group).
Install & Use
$ pip install aws-idc-list-user-permissions
$ aws-idc-list-user-permissions
Ensure that the you run this in the account where AWS Identity Center (previously AWS SSO) is setup, and the in the correct region. You may supply a region and aws profile if you use the non default:
$ aws-idc-list-user-permissions --profile my-org-profile --region us-east-1
Output
The script outputs two files, a short 5 column CSV, and a long jsonl file.
The jsonl file contains all details about the user, account, permission set, and group (if applicable), in a denormalized jsonl file. This file contains one json document per line, to make discovery easy.
The csv file contains only the 5 columns:
- User Name (this is the user's display name in AWS IDC)
- Account Name (the name of the account in AWS Organizations)
- Permission Set Name (the name of the permission set)
- InheritfromGroup (a column to indicate if the user inherited the permissions from a group or not)
- GroupName (if the user inherited this permission set from a group, this is the name of that group)
Notes
If an account or permission set exists with no users attached to it, this report will not have a item on the list for it. Only permissions sets with account assignments associated with actual users will appear on the list.
Groups with no users as members will not appear on the list.
The managed policies and inline policies for each permission set is available in the jsonl file on a per line basis.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Hashes for aws_idc_list_user_permissions-0.2.0.tar.gz
Algorithm | Hash digest | |
---|---|---|
SHA256 | 1c6da65fc6a46f18b346f996d45952eb6fb93040e8cdd9a156367e9e26b7e2a2 |
|
MD5 | 2d523620dd75c54f6746eeb67df9de42 |
|
BLAKE2b-256 | c0ce6be164bc7cfea09f4441a7f88e48b302be36adb57b54b4ffdea6c8be25d7 |
Hashes for aws_idc_list_user_permissions-0.2.0-py3-none-any.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | 6dce30263d9f87a3182763b16a3e6d224940f869340098ceb50e5218f326d3c5 |
|
MD5 | 6cdad617535f2b010c119a43decaf6ac |
|
BLAKE2b-256 | bdea34aab818a11f5fe682f0c2a0fb1d52f6fad4cf8d5759b871ac38355737d6 |