AWS Governance Lab
Hands-on lab showing how to implement AWS governance controls in a sandbox environment.
Identity Center Configuration

Identity Center assignments — mapping users and groups to AWS accounts.

Multi-Factor Authentication required — enforcing stronger account protection.

SSO Portal tiles — users only see accounts they are assigned to.

User account metadata — audit evidence for account ownership and attributes.
IAM Guardrails

Billing IAM access restricted — enforcing separation of duties and least privilege.
Outcomes
- Identity Center fully configured with MFA enforced.
- Clear SSO portal access only to authorized accounts.
- Evidence screenshots provide audit-ready proof of controls.