Trusted identity propagation with Amazon EMR
The following diagram shows a trusted identity propagation configuration for Amazon EMR Studio using Amazon EMR on Amazon EC2 with access control provided by Amazon Lake Formation and Amazon S3 Access Grants.

Supported client-facing applications
-
Amazon EMR Studio
To enable trusted identity propagation, follow these steps:
-
Set up Amazon EMR Studio as the client-facing application for Amazon EMR cluster.
-
Recommended: Amazon Lake Formation and Amazon S3 Access Grants to provide fine-grained access control to Amazon Glue Data Catalog and underlying data locations in S3.