CanEnterAccount

Source can obtain a principal/session inside the target AWS account.

cross_boundary CONTROL nature: derived walkable weight 1 high value
Identity  ── CanEnterAccount ──▸  Account

Source types

Identity

Target types

States

ACTIVE CONDITIONAL POTENTIAL BLOCKED UNKNOWN

Derivation

naturederived

Rules that emit CanEnterAccount 15

A management-account principal that can assume OrganizationAccountAccessRole enters the member account as full admin.
awsderived
Cross-account issuance on a CA whose certs are trusted in the owner account enters that account.
awsderived
cloudformation:CreateStackInstances / UpdateStackSet in the admin account deploys to target accounts, executing as the StackSet execution role there - a cross-account foothold.
awsderived
A cross-account principal that can start or modify a CodeBuild build gains a foothold in the project's account via the service role.
awsderived
A management-account principal that can assume AWSControlTowerExecution enters every enrolled member account as administrator.
awsderived
Creating a managed account via Account Factory yields a new account pre-seeded with an admin role the creator can assume - creation is entry.
awsderived
Cross-account decrypt that unlocks THIS account's credentials is an account foothold.
awsderived
Cross-account principal that can run code in a function enters this account.
awsderived
Cross-account read of a secret that is credentials for a local identity is a foothold in this account.
awsderived
A principal in account B provisioning a product from a portfolio shared by account A (servicecatalog:ProvisionProduct) causes resources to be deployed in account A as the account-A launch role. The receiving-account principal effectively gains a foothold in account A via the launch role's permissions.
awsderived
A consumer reads a RAM-shared SecureString whose creds grant the owning account.
awsderived
A principal in account A that can execute commands on an instance in account B, which runs as a role in account B, gains a foothold in account B.
awsderived
Assuming/federating into a role in another account = entering it.
awsderived
Federating into a Role homed in an AWS account gives the federated principal a foothold in that account.
derived
Control of a parent administrative boundary inherits transitively to every descendant boundary and resource via Contains*.
derived
move · open · esc close