Setting up hybrid access mode - common scenarios - Amazon Lake Formation
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Setting up hybrid access mode - common scenarios

As with Lake Formation permissions, you generally have two types of scenarios in which you can use hybrid access mode to manage data access: Provide access to principals within one Amazon Web Services account and provide access to an external Amazon Web Services account or principal.

This section provides instructions for setting up hybrid access mode in the following scenarios:

Manage permissions in hybrid access mode within one Amazon Web Services account
  • Converting a Lake Formation resource to a hybrid resource – You are currently using Lake Formation to manage access for tables in a database for all principals in your account but want to use Lake Formation only for specific principals. You want to provide access to new principals by using IAM permissions for Amazon Glue and Amazon S3 on the same database and tables.

Manage permissions in hybrid access mode across Amazon Web Services accounts
Setting up hybrid access mode – High-level steps
  1. Register the Amazon S3 data location with Lake Formation by selecting Hybrid access mode.

  2. Principals must have DATA_LOCATION permission on a data lake location to create Data Catalog tables or databases that point to that location.

  3. Set the Cross-account version setting to Version 4.

  4. Grant fine-grained permissions to specific IAM users or roles on databases and tables. At the same time, make sure to set Super or All permissions to the IAMAllowedPrincipals group on the database and all or selected tables in the database.

  5. Opt in the principals and resources. Other principals in the account can continue accessing the databases and tables using IAM permission policies for Amazon Glue and Amazon S3 actions.

  6. Optionally clean up IAM permission policies for Amazon S3 for the principals that are opted in to use Lake Formation permissions.