aws-sso-cli
aws-sso-cli copied to clipboard
Discover role and account tags
admins can tag role and accounts:
- iam:ListRoleTags
- organizations:ListTagsForResource (account, OU, root)
this is going to be very expensive for users with lots of accounts. Would probably need to be opt-in? Not sure how useful these tags are to users... would require admins to be organized.
most users will not have access to organizations:ListTagsForResource. The iam:listRoleTags seems more useful, but very expensive.