Britive platform release 2026.08.02 is now live in production.

Onboarding AWS Account Access

Prev Next

As mentioned earlier in the Introduction of this guide, you can choose to onboard an AWS Account Access application when your AWS organization has both management account(s) and member accounts.

Steps for Onboarding an AWS Account Access Application

Perform the following steps for adding an AWS Account Access tenant application to Britive:

Note:

Before onboarding the application, ensure that you have completed the onboarding prerequisites mentioned in the section Prerequisites.

  1. Log in to the Britive application with administrator privileges.

  2. Click System admin > Tenant Applications.

  3. From the Tenant Applications page, click Create Application.

  4. On the Add Application page, click the Add (+) sign next to the AWS Account Access application. The Create Application page is displayed. On this page, you can see two tabs—Application and Settings.

  5. In the Application tab, enter the following values:

    1. Enter the Application Name.

    2. Enter the Application Description (optional step).

    3. Check Show AWS Account Numbers if you want the AWS account numbers to be displayed in the tenant application.

    4. Under Account Mapping, select Email mapping to map the user's email with the AWS account.

  6. Click Next. The Settings tab is displayed.

  7. In the Settings tab, enter the following values:

    • Connection Properties:

      • Management Account ID corresponds to the Account ID of the Management AWS Account of the user.

      • Identity Provider Name corresponds to the Provider name added while adding the identity provider to the AWS account. For more information, see Configuring an Identity Provider in AWS.

      • AWS Account Access Application ARN corresponds to the unique Amazon Resource Name (ARN) that identifies the built-in AWS Account Access application within AWS IAM Identity Center.

      • Integration Role Name corresponds to the name of the IAM role within the AWS account of the user. If the role is created with AWS Resource Path, you need to prefix the resource path without a leading slash symbol. For example: If the ARN of the role is arn:aws:iam::0000000000:role/Security/IAM/Britive_Integration_Role2, you need to enter Security/IAM/Britive_Integration_Role2 in the role name.

      • Duration of the backend AWS connection (in hours) corresponds to the Maximum Session Duration in an IAM role within the AWS account of the user. For more information, see Configuring IAM Roles.

      • The region corresponds to the AWS region to be used for STS to generate temporary AWS access keys.

      • Login URL corresponds to the AWS access portal URL (provided by AWS IAM Identity Center). This is the dedicated sign-in link that users use to authenticate and access the various AWS accounts they have been granted permissions to.

    • Advanced Settings:

      • Source Identity Attribute: This corresponds to the attribute value for setting Source Identity in CloudTrail logs. Select an attribute from the dropdown list to be set in CloudTrail logs. Select None to not set any source identity.

    • Profile Settings: Configure the maximum session duration for profiles. You can select the duration between 15 minutes to 7 calendar days. This allows to setup expiration duration for each profile while creating/updating the profile up to this configured value. If existing profiles are created with more than 12 hours and the above setting is changed, then it cannot be lowered until all profiles are updated with a lower expiration duration.

  8. Click Save and Test. If the AWS application is configured with the correct values, then the success message is displayed.

  9. Clicking the Save and Test button, after adding incorrect configuration value(s) in the Settings tab, while configuring an AWS application, displays the relevant error message.