- AWS Quicksight - Discussion
- AWS Quicksight - Useful Resources
- AWS Quicksight - Quick Guide
- Developer Responsibilities
- AWS Quicksight - AWS SDKs
- AWS Quicksight - Embedding Dashboard
- AWS Quicksight - Managing IAM Policies
- AWS Quicksight - Edition Type
- AWS Quicksight - Managing Quicksight
- AWS Quicksight - Dashboards
- AWS Quicksight - Sharing Analysis
- AWS Quicksight - Using Parameters
- AWS Quicksight - Creating Story
- AWS Quicksight - Insights
- Using Filters to a Visual
- AWS Quicksight - Adding Visuals
- AWS Quicksight - Creating New Analysis
- AWS Quicksight - Editing Datasets
- AWS Quicksight - Data Source Limit
- AWS Quicksight - Using Data Sources
- AWS Quicksight - Landing Page
- AWS Quicksight - Overview
- AWS Quicksight - Home
Selected Reading
- Who is Who
- Computer Glossary
- HR Interview Questions
- Effective Resume Writing
- Questions and Answers
- UPSC IAS Exams Notes
AWS Quicksight - Managing IAM Popcies
To manage IAM popcies for Quicksight account, you can use root user or IAM credentials. It is recommended to use IAM credentials to manage resource access and popcies instead of root user.
Following popcies are required to signup and use Amazon Quicksight −
Standard Edition
ds:AuthorizeApppcation
ds:CheckApas
ds:CreateApas
ds:CreateIdentityPoolDirectory
ds:DeleteDirectory
ds:DescribeDirectories
ds:DescribeTrusts
ds:UnauthorizeApppcation
iam:CreatePopcy
iam:CreateRole
iam:ListAccountApases
quicksight:CreateUser
quicksight:CreateAdmin
quicksight:Subscribe
Enterprise Edition
Apart from the above mentioned popcies, below permissions are required in enterprise edition −
quicksight:GetGroupMapping
quicksight:SearchDirectoryGroups
quicksight:SetGroupMapping
You can also allow a user to manage permissions for AWS resources in Quicksight. Following IAM popcies should be assigned in both editions −
iam:AttachRolePopcy
iam:CreatePopcy
iam:CreatePopcyVersion
iam:CreateRole
iam:DeletePopcyVersion
iam:DeleteRole
iam:DetachRolePopcy
iam:GetPopcy
iam:GetPopcyVersion
iam:GetRole
iam:ListAttachedRolePopcies
iam:ListEntitiesForPopcy
iam:ListPopcyVersions
iam:ListRoles
s3:ListAllMyBuckets
To prevent an AWS administrator to unsubscribe from Quicksight, you can deny all users “quicksight:Unsubscribe”
IAM popcy for dashboard embedding
To embed an AWS Quciksight dashboard URL in web page, you need the following IAM popcies to be assigned to the user −
{ "Version": "2012-10-17", "Statement": [ { "Action": "quicksight:RegisterUser", "Resource": "*", "Effect": "Allow" }, { "Action": "quicksight:GetDashboardEmbedUrl", "Resource": "arn:aws:quicksight:us-east-1: 868211930999:dashboard/ f2cb6cf2-477c-45f9-a1b3-639239eb95d8 ", "Effect": "Allow" } ] }
You can manage and test these roles and popcies using IAM popcy simulator in Quicksight. Below is the pnk to access IAM Popcy simulator −
Advertisements