AWS

4 Mins Read

Sharing resource across the account using AWS Resource Access Manager

Voiced by Amazon Polly

AWS Organizations enables you to be centralized account management as you grow and scale your AWS resources. But it’s very difficult to manage, provision and control AWS resources in the organizations. If you have an AWS account which is a part of an AWS organization, it is very easy to share the resources with accounts in the organization and Organization Unit.

Transform Your Career with AWS Certifications

  • Advanced Skills
  • AWS Official Curriculum
  • 10+ Hand-on Labs
Enroll Now

AWS Resource Access Manager (RAM)

If AWS account is managed by AWS Organization, then Resource Access Manager is used to share the resources you have created in one account with the other within the specific Organization Unit and specific AWS account by account id. When you share any resource with account outside the organization, those accounts will receive an invitation. The owner of those accounts need to accept the invitation, so the resources will be available for use.

Benefits of AWS RAM

Minimize operation overhead: To avoid the need to provision duplicate resource in all available accounts, create the resource in one account and share it with other account.

Security: Having shared resource and using single set of policies, minimize the security management overhead. If same set of resource are available in different account, then implementing identical policies will be a challenging task and will also increase the management overhead and redundancy.

How resource sharing works

  • You have account (Owning Account) where you can create the resource and share it with other accounts (Consuming account) by granting access for principals of that account.
  • When consuming account access the shared resources, the resources are available in the same region where owning account shared the resources.
  • When owning account share resources with other account, permissions and quotas remain unchanged.

Task1: Steps to share the resources from Owning account

  • Select the region where your created resource is available to share. Move to Resource Access Manager service. Select resource share from shared by me and create resource share.

 

  • Specify resource share details
    • Resource Share Name

    • Choose the resources to add to the resource share and select the appropriate resource

 

  • Associate managed permissions as per your need

 

  • Grant access to principals: Specify the principals that are allowed access to the shared resources. A principal can be any of the following: An entire organization or organizational unit (OU) in AWS Organizations, an AWS account, IAM role, or IAM user.

 

  • Review and create resource share.

 

  • Resource is successfully shared. To check if the resource is shared, go to shared by me and select Shared resources

Task2: Steps to access the resources in Consuming account

  • Log in to the account (Consuming Account) from where you need to access the resources.
  • Select the region from where your need to access the resource. Move to Resource Access Manager service and check which resources are shared with your account by selecting resource share & shared resources from shared with me.

 

  • Move to the VPC dashboard, select the subnets and you can identify, one subnet is shared with your account.

 

  • Now you can use shared subnet for your other resources.

Expertly Migrate diverse Microsoft Workloads to AWS with CloudThat, Your Advanced AWS Migration Partner

  • Seamless Migration
  • Cost Optimization
  • Usage Efficiency
Talk to Expert

About CloudThat

CloudThat is a leading provider of Cloud Training and Consulting services with a global presence in India, the USA, Asia, Europe, and Africa. Specializing in AWS, Microsoft Azure, GCP, VMware, Databricks, and more, the company serves mid-market and enterprise clients, offering comprehensive expertise in Cloud Migration, Data Platforms, DevOps, IoT, AI/ML, and more.

CloudThat is the first Indian Company to win the prestigious Microsoft Partner 2024 Award and is recognized as a top-tier partner with AWS and Microsoft, including the prestigious ‘Think Big’ partner award from AWS and the Microsoft Superstars FY 2023 award in Asia & India. Having trained 650k+ professionals in 500+ cloud certifications and completed 300+ consulting projects globally, CloudThat is an official AWS Advanced Consulting Partner, Microsoft Gold Partner, AWS Training PartnerAWS Migration PartnerAWS Data and Analytics PartnerAWS DevOps Competency PartnerAWS GenAI Competency PartnerAmazon QuickSight Service Delivery PartnerAmazon EKS Service Delivery Partner AWS Microsoft Workload PartnersAmazon EC2 Service Delivery PartnerAmazon ECS Service Delivery PartnerAWS Glue Service Delivery PartnerAmazon Redshift Service Delivery PartnerAWS Control Tower Service Delivery PartnerAWS WAF Service Delivery Partner and many more.

To get started, go through our Consultancy page and Managed Services PackageCloudThat’s offerings.

Share

Comments

    Click to Comment

Get The Most Out Of Us

Our support doesn't end here. We have monthly newsletters, study guides, practice questions, and more to assist you in upgrading your cloud career. Subscribe to get them all!