Get a Demo
Under Attack?
Diagram showing a flowchart with three main branches. The branches have icons representing a lock, a sun, and a shield, each leading to cloud and gear icons. The word upwind is in the top left.

Monitor & Secure Cross-Account Roles with Upwind’s Non-Human Identity Security (NHI)

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Denise Ashur July 10, 2024

Monitor & Secure Cross-Account Roles with Upwind’s Non-Human Identity Security (NHI)

Upwind’s Non-Human Identity (NHI) Security streamlines your identity management and gives you the ability to easily view cross-account roles and their associated permissions.

Cross-account roles are incredibly useful for organizations with multiple AWS accounts and permissions, but they can also be difficult to monitor and secure. Upwind helps solve this problem by providing increased visibility and streamlining the monitoring of cross-account roles.

What are Cross-Account Roles?

Cross-account roles are IAM roles that enable an IAM user or AWS service in one AWS account to access resources in another AWS account. 

Screenshot-2024-07-08-at-12.54.30%E2%80%AFPM-1024x660

Cross-account roles are generally used to establish and grant access by sharing temporary security credentials between an account that is “trusting entity” and an account that is a “trusted entity” in AWS. In this case, the trusting entity contains resources and services that will be accessed by users belonging to the trusted entity, which is granted through a “trust policy.”

Once a trust relationship has been set up and the cross-account role is established, the user or group can then assume a role with temporary security credentials that allow it to access resources in the trusting account. 

For example, if you wanted to allow a different AWS account to access a service in your account, such as a DynamoDB table, you could use a cross-account role to leverage an IAM role in your account (the “trusting entity”) and allow the other AWS account user (the “trusted entity”) to assume it for a specific duration, rather than creating an IAM user in your account and assigning it a long-term password or access keys.

Similarly, if you wanted to allow an EC2 instance in another account to access a service in your account, such as Apache Airflow, you could use a cross-account role to allow them to assume an IAM role in your account in order to access it for a set period of time.

How to Secure Cross-Account Roles

Upwind gives you the ability to view all cross-account roles and relevant information about their uses and permissions, answering the question of “who can assume a role, and what permissions do they have on which resources?”

Screenshot-2024-07-08-at-12.58.34%E2%80%AFPM-1024x798

Using the Upwind’s Non-Human Identity Security, you can view the following:

  • Cross-Account Role Details: Discover the name of the role, the associated account, and when it was created.
  • Authorization Graph: Visually understand who can assume a role and what permissions they have on which resources.
  • Trusted Entities: View a list of AWS users who are “trusted entities,” meaning that a trust policy has granted them access to an account’s resources and services, or allowed them to assume a particular IAM role and its associated permissions.
  • Resources overview: View all resources currently assuming a given  role 
  • Highly Privileged Permissions: Automatically identify if a cross-account role’s permissions include highly privileged permissions.
Screenshot-2024-07-08-at-12.56.31%E2%80%AFPM-1024x498

Use Upwind’s Non-Human Identity Security to easily monitor your cross-account roles, view resources currently assuming roles, and easily understand who can assume a role and what permissions they have on which resources
To learn more about Upwind’s Non-Human Identity Security, visit the Upwind Documentation Center (login required) or schedule a demo.

Contents

Further Reading

The Risk Isn't What You Prompt, It's What You Built.

The Risk Isn’t What You Prompt, It’s What You Built

Key Takeaways: Agentic AI security is an architecture problem, not a policy problem. Most organizations have adopted AI agents in the form of coding assistants, autonomous workflow tools, internal chatbots connected to production systems, but without establishing the foundational security frameworks those systems require. The adoption pressure is real. Telling your engineering team to stop…
Upwind is a Visionary Leader in Frost & Sullivan report

Upwind Named a Strong Visionary Leader in Frost & Sullivan’s 2026 Cloud/Application Runtime Security Radar

We're excited to share that Frost & Sullivan has recognized Upwind as a Strong Visionary Leader in the Frost Radar™: Cloud/Application Runtime Security, 2026. This recognition highlights the company's innovation, growth, and leadership in the emerging Cloud-Native Application Detection and Response (CNADR) market. For us, the recognition is meaningful not simply because of where Upwind…
API Custom Threat Detection

Upwind brings Custom Detection Policies for APIs

Every API has a different risk profile. An internal billing endpoint and a public-facing authorization endpoint don't fail the same way. They don't get attacked the same way either. A generic ruleset can't account for that. Custom rules can, and now those rules can see sensitive data too. This new release brings two things together…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS