Res_AWS Identity Access Management_AWS STS Alternate_48 imageIcon source: AWS
CLOUD SERVICE · AWS

AWS Security Token Service (AWS STS)

AWS Security Token Service (AWS STS) is a web service that enables you to request temporary, limited-privilege credentials for AWS Identity and Access Management (IAM) users or for users that you authenticate (federated users).

Cloud Services Hub →

Free AWS Security Token Service (AWS STS) tools

What is AWS Security Token Service (AWS STS)

Read the extensive description

AWS Security Token Service (AWS STS) is a web service that enables you to request temporary, limited-privilege credentials for AWS Identity and Access Management (IAM) users or for users that you authenticate (federated users). Its primary function is to enhance the security posture of your AWS environment by enforcing the principle of least privilege, ensuring that entities within your environment have only the permissions they absolutely need to accomplish their tasks, and only for a limited period. This mitigates the risks associated with long-standing credentials which, if compromised, could lead to unauthorized access to your resources. 

 

AWS STS plays a crucial role in the management of temporary credentials. It allows the creation of unique, temporary credentials that can be assigned to users or systems, automatically expiring after a definable period. This effectively reduces the risk of credential leakage or misuse since these credentials, even if compromised, are only valid for a short duration. Additionally, AWS STS provides the ability to grant cross-account access without the need to share long-term credentials or define explicit trust relationships between AWS accounts. This facilitates secure collaboration between different business units or companies while maintaining tight control over resource access. 

 

One of the distinguished features of AWS STS is its integration with other AWS services and identity providers. It facilitates the federation of user identities by enabling users to sign in with their credentials from external identity providers like corporate directories, thus avoiding the need to create separate IAM users in AWS. This capability not only streamlines user access management but also leverages the security mechanisms of the external identity providers, such as multi-factor authentication. 

 

AWS STS supports several use cases, including granting access to AWS resources from applications running on EC2 instances, managing permissions for applications on mobile devices or IoT devices, and providing access to AWS resources for users from external systems. By granting temporary access, AWS STS ensures that the principle of least privilege can be applied more effectively and securely across these diversified environments. 

 

In operational terms, AWS STS is easy to implement through the AWS Management Console, the AWS Command Line Interface (CLI), or the AWS SDKs. It allows the generation of credentials dynamically, thereby enabling automation and integration into various application flows. The service itself is designed to be highly available and resilient, ensuring that the mechanism for generating and distributing temporary credentials does not become a bottleneck or single point of failure in your architecture. 

 

In conclusion, AWS Security Token Service is a critical component of AWS's security and identity services, offering a robust mechanism for managing temporary credentials and enabling secure, efficient access management across AWS environments. Its capabilities support the core security principles of least privilege and defense in depth, making it an indispensable tool for architects and developers looking to design secure cloud-based solutions.

Key AWS Security Token Service (AWS STS) Features

AWS Security Token Service (AWS STS) features include the creation of temporary credentials, permission control through fine-grained access, integration with external identity providers for federated access, facilitation of cross-account access, support for multi-factor authentication, and operation as a globally available service.

Temporary Credentials

AWS Security Token Service allows the creation of temporary, short-term credentials that can be used to access AWS resources. These temporary credentials are a more secure alternative to using long-term access keys.

Permission Control

With AWS STS, you can define specific permissions for the temporary credentials, ensuring that applications and users have only the access they need, thus following the principle of least privilege.

Active Directory Integration

AWS STS supports federated identities, allowing users to authenticate with external identity providers (like Active Directory or LinkedIn) and then assume an IAM role with permissions for accessing AWS resources.

Cross-Account Access

It facilitates cross-account access, enabling the creation of trust relationships between AWS accounts or between an AWS account and an external identity provider. This simplifies managing permissions across AWS accounts.

Multi-Factor Authentication Support

AWS STS supports multi-factor authentication (MFA), adding an extra layer of security by requiring users to provide additional verification before being granted the temporary credentials.

Global Service

AWS STS is a global service, meaning the tokens obtained can be used with AWS services across all regions, enhancing convenience and flexibility in managing access to resources.

AWS Security Token Service (AWS STS) Use Cases

AWS Security Token Service (AWS STS) use cases include providing temporary access to AWS resources, enabling secure cross-account access, facilitating federation with external identity systems, and enhancing security with support for Multi-factor Authentication (MFA).

Temporary Access for Users

AWS STS allows the creation of temporary security credentials for users who need to access AWS resources for a short-term project or task. This eliminates the need to manage long-term credentials for every user, enhancing security by automatically expiring credentials.

Cross-account Access

It enables secure delegation of access to resources across different AWS accounts without having to share long-term access keys. By using AWS STS, administrators can grant users from one AWS account permissions to access resources in another account in a secure and controlled manner.

Federation with Identity Systems

AWS STS facilitates federation with external identity systems such as Active Directory, SAML 2.0-compliant identity providers, or other OpenID Connect (OIDC) compliant providers, enabling users to sign in using their existing corporate credentials to access AWS resources.

Multi-factor Authentication (MFA) for Enhanced Security

AWS STS supports the use of Multi-factor Authentication (MFA), adding an additional layer of security. When temporary security credentials are requested, requiring MFA can significantly reduce the risk of unauthorized access.

AWS Security Token Service (AWS STS) pricing models

AWS STS is free for use, with no direct charges for the service itself, but costs may be incurred for requests over 100,000 per month outside of free tier regions and for using the temporary credentials with other AWS services.

AWS Security Token Service (AWS STS) Pricing

AWS Security Token Service (AWS STS) is essentially a free-to-use feature for AWS account holders. However, while there is no direct charge for using AWS STS, any requests made to AWS services using the temporary security credentials generated by AWS STS will incur standard AWS service fees according to the particular service’s pricing model. Additionally, AWS charges for STS requests in AWS Regions outside the AWS Free Usage Tier, which consists of the following regions: US East (N. Virginia), US West (Oregon), and EU (Ireland). As of the last update, the first 100,000 AWS STS Requests per month are free, and beyond this volume, there is a fee for additional requests.

Services AWS Security Token Service (AWS STS) integrates with

Amazon EMR image Amazon EMR

Allows Amazon EMR clusters to use temporary credentials for accessing data and services securely.

Open Amazon EMR →
AWS Glue image AWS Glue

Provides temporary security credentials to access data stored in S3, DynamoDB, and other resources for ETL jobs.

Open AWS Glue →
Amazon Redshift image Amazon Redshift

Uses temporary security credentials to control access to Redshift clusters and data.

Open Amazon Redshift →
AWS Step Functions image AWS Step Functions

Step Functions use temporary credentials to execute state machines that interact with other AWS services.

Open AWS Step Functions →
Amazon EC2 image Amazon EC2

Allows EC2 instances to assume roles and gain temporary credentials to perform various tasks.

Open Amazon EC2 →
Amazon DynamoDB image Amazon DynamoDB

Grants temporary security credentials to interact with DynamoDB tables while adhering to the principle of least privilege.

Open Amazon DynamoDB →
Amazon RDS image Amazon RDS

Enables RDS instances or users to get temporary credentials for accessing databases securely.

Open Amazon RDS →
Amazon API Gateway image Amazon API Gateway

Integrates with API Gateway to grant temporary access tokens for API calls.

Open Amazon API Gateway →
Amazon SageMaker image Amazon SageMaker

Grants temporary credentials to SageMaker for accessing data stores and other resources needed for machine learning tasks.

Open Amazon SageMaker →
AWS CloudFormation image AWS CloudFormation

Uses temporary security credentials to provision and manage AWS resources defined in CloudFormation templates.

Open AWS CloudFormation →
Amazon CloudWatch image Amazon CloudWatch

Allows temporary access to CloudWatch for monitoring and managing AWS resources.

Open Amazon CloudWatch →
AWS Identity and Access Management image AWS Identity and Access Management (IAM)

AWS STS works with IAM to help manage and control temporary security credentials for users and roles.

Open AWS Identity and Access Management (IAM) →
AWS Lambda image AWS Lambda

Lambda functions can assume roles and get temporary security credentials to access other AWS services.

Open AWS Lambda →
Amazon Simple Storage Service image Amazon S3

Uses temporary security credentials from AWS STS to grant access to S3 buckets and objects securely.

Open Amazon S3 →