Transfer Family server should use a managed identity provider
Medium
AWS
General
aws-transfer-server-managed-identity
Applies to
AWS::Transfer::Server
What CGPulse checks
A resource passes this rule when identityProviderType must not equal SERVICE_MANAGED. Anything else is reported as a finding with the evaluated property value attached as evidence.
How to fix it
Use a custom or directory-based identity provider to integrate with enterprise identity systems. In AWS Console: Transfer Family > Servers > Edit > set Identity provider. See: https://docs.aws.amazon.com/transfer/latest/userguide/custom-identity-provider-users.html
Terraform
resource "aws_transfer_server" "{name}" {
identity_provider_type = "API_GATEWAY"
}
Compliance frameworks
Is your environment compliant with this rule?
CGPulse checks it — and 621 others — against your Azure and AWS accounts with read-only access.
Related AWS rules
- ACM certificate must be eligible for renewal
- ACM certificate must be in issued status
- Amplify app should have basic auth disabled for production
- API Gateway REST API must have an endpoint configuration
- API Gateway V2 API must be properly configured
- App Runner service must have encryption enabled
- AppSync API must have logging configured
- AppSync API must have X-Ray tracing enabled