About This Architecture
Just-in-time (JIT) access architecture combining CyberArk Idira with AWS IAM Identity Center and STS to enforce time-bound, approval-driven access without persistent credentials. Employees and contractors authenticate via Okta with MFA, submit JIT requests evaluated by Idira policy engine, and receive temporary STS tokens valid only for their approved session window. AWS resources (EC2, S3, RDS) are accessed through SAML 2.0 federation with automatic session expiration and full audit logging via Idira. This pattern eliminates standing privileges, reduces blast radius from credential compromise, and meets compliance requirements for PAM and zero-trust architecture. Fork and customize this diagram on Diagrams.so to adapt approval workflows, identity sources, or resource scopes for your organization.