Lab 1 · Afternoon session · runs with Module 03

Deploy cloud resources from AWS Service Catalog

You will build a portfolio, publish a product into it, constrain what that product may do, entitle a role to see it, and then swap hats and launch it as a consumer. Five tasks, one idea: a preventive control can hand out capability without handing out permission.

Portfolio & product Launch constraint IAM entitlement Hands-on ~45 minutes