Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “session duration”
7 publicationsRespond to an exposed AWS access key beyond the quarantine policy
In a published test, AWS attached its quarantine policy 10 seconds after a key leaked, but the policy denies actions without ending access. This playbook covers what it leaves open, which credentials outlive the key, and the order of containment.
Detection & response · Amazon Web Services / GitHub / Google Cloud · By Cloud Security DeskGive a SaaS vendor an AWS role without creating a confused deputy
A vendor's cross-account role is safe only if your trust policy demands an exact external ID, the vendor's backend generates and enforces it per tenant, and your reviews catch drift and offboard the role.
Identity & access · Amazon Web Services · By Cloud Security DeskCompare just-in-time privileged access in AWS, Azure and Google Cloud
Entra PIM and Google Cloud PAM make roles temporary natively, while AWS relies on TEAM or partner tools. All three end elevation by removing an assignment, and sessions, caches and minted tokens can keep running.
Identity & access · Amazon Web Services / Microsoft Azure / Microsoft Entra / Google Cloud · By Cloud Security DeskProve Identity Center permission changes reached every account
A permission-set change is complete only when the intended accounts, account-local policies, provisioning results and assignments have converged.
Identity & access · AWS · By Cloud Security DeskWorkload federation across clouds needs separate trust decisions
Cross-cloud federation adds trust decisions, not a portable permission system. Map each credential and resource grant before moving a runtime workload.
Identity & access · AWS / Google Cloud / Microsoft Entra · By Cloud Security DeskDefine the expiry boundary for Entra privileged access
PIM records activation and expiry, but the protected application still determines when changed authority takes effect. Review both sides of that boundary.
Identity & access · Microsoft Entra · By Cloud Security DeskThe permission path you didn’t review
Cross-account trust rarely fails at the obvious policy. The risk lives in the path between identities, conditions, and inherited access.
Identity & access · AWS · By Umair Akbar and Ahmed Elshekh