Delegate who can manage your password policies - Amazon Directory Service
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Delegate who can manage your password policies

You can delegate permissions to manage password policies to specific user accounts you created in your Amazon Managed Microsoft AD by adding the accounts to the Amazon Delegated Fine Grained Password Policy Administrators security group. When an account becomes a member of this group, the account has permissions to edit and configure any of the password policies listed previously.

To delegate who can manage password policies
  1. Launch Active Directory administrative center (ADAC) from any managed EC2 instance that you joined to your Amazon Managed Microsoft AD domain.

  2. Switch to the Tree View and navigate to the Amazon Delegated Groups OU. For more information about this OU, see What gets created with your Amazon Managed Microsoft AD Active Directory.

  3. Find the Amazon Delegated Fine Grained Password Policy Administrators user group. Add any users or groups from your domain to this group.