Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “session duration”

7 publications
Technical guideSource-based analysis

Respond to an exposed AWS access key beyond the quarantine policy

In a published test, AWS attached its quarantine policy 10 seconds after a key leaked, but the policy denies actions without ending access. This playbook covers what it leaves open, which credentials outlive the key, and the order of containment.

Detection & response · Amazon Web Services / GitHub / Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Give a SaaS vendor an AWS role without creating a confused deputy

A vendor's cross-account role is safe only if your trust policy demands an exact external ID, the vendor's backend generates and enforces it per tenant, and your reviews catch drift and offboard the role.

Identity & access · Amazon Web Services · By Cloud Security Desk
Technical guideSource-based analysis

Compare just-in-time privileged access in AWS, Azure and Google Cloud

Entra PIM and Google Cloud PAM make roles temporary natively, while AWS relies on TEAM or partner tools. All three end elevation by removing an assignment, and sessions, caches and minted tokens can keep running.

Identity & access · Amazon Web Services / Microsoft Azure / Microsoft Entra / Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Prove Identity Center permission changes reached every account

A permission-set change is complete only when the intended accounts, account-local policies, provisioning results and assignments have converged.

Identity & access · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Workload federation across clouds needs separate trust decisions

Cross-cloud federation adds trust decisions, not a portable permission system. Map each credential and resource grant before moving a runtime workload.

Identity & access · AWS / Google Cloud / Microsoft Entra · By Cloud Security Desk
Research noteSource-based analysis

Define the expiry boundary for Entra privileged access

PIM records activation and expiry, but the protected application still determines when changed authority takes effect. Review both sides of that boundary.

Identity & access · Microsoft Entra · By Cloud Security Desk
Research reportIllustrative analysis

The permission path you didn’t review

Cross-account trust rarely fails at the obvious policy. The risk lives in the path between identities, conditions, and inherited access.

Identity & access · AWS · By Umair Akbar and Ahmed Elshekh