Delegating who can manage your Amazon Managed Microsoft AD password policies
You can delegate permissions to manage password policies to specific user accounts you created in your Amazon Managed Microsoft AD by adding the accounts to the Amazon Delegated Fine Grained Password Policy Administrators security group. When an account becomes a member of this group, the account has permissions to edit and configure any of the password policies listed previously.
To delegate who can manage password policies
-
Launch Active Directory administrative center (ADAC)
from any managed EC2 instance that you joined to your Amazon Managed Microsoft AD domain. -
Switch to the Tree View and navigate to the Amazon Delegated Groups OU. For more information about this OU, see What gets created with your Amazon Managed Microsoft AD.
-
Find the Amazon Delegated Fine Grained Password Policy Administrators user group. Add any users or groups from your domain to this group.