https://www.youtube.com/watch?v=-XARG9W2bGc
- SAML federation at scale
- Automate onboarding
- Allow a cross-account trust to create SAML providers w/ MFA from master/payer acct (15:47)
- This allows bootstrapping new accounts by a small group of admins w/ real IAM accts or root acct
- automate integrating each subaccount's SAML ID provider
- automate deployment of subaccount IAM role & policies
- automate deployment of central directory groups/structure
- Allow a cross-account trust to create SAML providers w/ MFA from master/payer acct (15:47)
- Automate onboarding
- keep role definitions consistent across subaccounts