AWS::SSO::AssignmentResource Type definition for SSO assignmet
6 configurable properties. 6 required. Click a row to see details.
| Property | Type | Flags |
|---|---|---|
InstanceArn | string | RequiredCreate-only |
PermissionSetArn | string | RequiredCreate-only |
PrincipalId | string | RequiredCreate-only |
PrincipalType | string | RequiredCreate-only |
TargetId | string | RequiredCreate-only |
TargetType | string | RequiredCreate-only |
A minimal template with required properties and common optional ones.
AWSTemplateFormatVersion: "2010-09-09"
Description: Sample template for AWS::SSO::Assignment
Resources:
MyResource:
Type: AWS::SSO::Assignment
Properties:
InstanceArn: "arn:aws:service:region:account:resource"
TargetId: "my-targetid"
TargetType: "AWS_ACCOUNT"
PermissionSetArn: "arn:aws:service:region:account:resource"
PrincipalType: "USER"
PrincipalId: "my-principalid"Permissions CloudFormation needs in your IAM role to manage this resource.
sso:CreateAccountAssignmentsso:DescribeAccountAssignmentCreationStatussso:ListAccountAssignmentsiam:GetSAMLProvideriam:CreateSAMLProvideriam:AttachRolePolicyiam:PutRolePolicyiam:CreateRolesso:ListAccountAssignmentsiam:GetSAMLProvideriam:ListRolePoliciessso:ListAccountAssignmentssso:DeleteAccountAssignmentsso:DescribeAccountAssignmentDeletionStatusiam:GetSAMLProvideriam:ListRolePoliciessso:ListAccountAssignmentsiam:ListRolePoliciesOur bi-weekly newsletter teaches hands-on AWS fundamentals. No certification fluff - just practical knowledge.
Subscribe to NewsletterInstanceArnThese properties cannot be changed after the resource is created. Updating them triggers a replacement.
InstanceArnTargetIdTargetTypePermissionSetArnPrincipalTypePrincipalId