Review IAM Identity Center permission-set session duration

Limit AWS account session duration according to the sensitivity of the permissions and the time needed for the work.

Description

The session_duration of an AWS IAM Identity Center permission set controls the lifetime of console and CLI sessions used to access AWS accounts with those permissions. Unnecessarily long sessions extend the time in which stolen credentials or sessions left on shared devices can be abused.

The default and minimum are one hour, with a maximum of 12 hours. Choose a duration appropriate for the permissions and the work. The AWS access portal sign-in session has a separate duration setting.

Potential impact

  • A stolen account session can be abused until it expires.
  • Another person may use a session left signed in on a shared device.

Remediation

  • Use the shortest practical duration for sensitive permissions and review the justification for longer sessions. PT1H is the supported minimum.
  • Verify the permission-set change and account reprovisioning. Manage portal sessions, MFA and incident-response session revocation separately.

Examples

These excerpts assume a data source that retrieves the Identity Center instance. Configure permission policies and account assignments separately.

Before

hcl
resource "aws_ssoadmin_permission_set" "example" {
  name             = "Example"
  description      = "An example"
  instance_arn     = tolist(data.aws_ssoadmin_instances.main.arns)[0]
  relay_state      = "https://s3.console.aws.amazon.com/s3/home?region=us-east-1#"
  session_duration = "PT2H"
}

After

hcl
resource "aws_ssoadmin_permission_set" "example" {
  name             = "Example"
  description      = "An example"
  instance_arn     = tolist(data.aws_ssoadmin_instances.main.arns)[0]
  relay_state      = "https://s3.console.aws.amazon.com/s3/home?region=us-east-1#"
  session_duration = "PT1H"
}

Explanation:

  • Before: Account sessions last two hours. Review the required work duration alongside the risk.
  • After: The account session duration is reduced to one hour. This does not end the portal session or immediately revoke every existing session.

References