Amazon Web Services - FAQs
Introduction
These FAQs provide an overview of the ¿ì»îÁÖÐÔÏ¢ AWS Cloud Platform (¿ì»îÁÖÐÔÏ¢ AWS).
¿ì»îÁÖÐÔÏ¢ Information Technology has embarked on a hybrid cloud strategy that enables ¿ì»îÁÖÐÔÏ¢ to transition to the cloud. The ¿ì»îÁÖÐÔÏ¢ AWS Cloud Platform provides the necessary baseline infrastructure for utilizing AWS cloud services while securely integrating with ¿ì»îÁÖÐÔϢ’s on-premise data centers.
¿ì»îÁÖÐÔÏ¢ AWS is an extension of ¿ì»îÁÖÐÔϢ’s on-premise network and datacenter. Users have the ability to seamlessly integrate and access resources between the on-premise and ¿ì»îÁÖÐÔÏ¢ AWS environments. Users already familiar with AWS will not notice a difference after logging in to their ¿ì»îÁÖÐÔÏ¢ AWS account. Lastly, users will not have to agree to AWS Terms and Conditions when the account is created.
Requesting a ¿ì»îÁÖÐÔÏ¢ AWS account is easy! ¿ì»îÁÖÐÔÏ¢ AWS is integrated with ¿ì»îÁÖÐÔÏ¢'s standard procurement process using purchasing orders (POs). Users need to have an approved PO from their respective department/college before a new ¿ì»îÁÖÐÔÏ¢ AWS account can be requested. ¿ì»îÁÖÐÔÏ¢ IT will work with the user to estimate cost and provide a quote that will be used to issue a PO. Once the PO is approved, navigate to the accountÌý.
¿ì»îÁÖÐÔÏ¢ AWS is integrated with ¿ì»îÁÖÐÔÏ¢'s single sign-on (SSO) process. Users can log in to their ¿ì»îÁÖÐÔÏ¢ AWS account by going to accountÌýÌýpage. Users are requested to enter their ¿ì»îÁÖÐÔÏ¢ issued user ID and password to log in.
Users can navigate to theÌýguest access pageÌýand select ‘Guest Access’ to grant others access to their ¿ì»îÁÖÐÔÏ¢ AWS account. Access can only be granted to valid ¿ì»îÁÖÐÔÏ¢ accounts.
The user who requested the account (account owner) has access to the account. Additionally, anyone the account owner shares access with will gain access to the account. ¿ì»îÁÖÐÔÏ¢ IT does not have access to your AWS account unless explicit permission is granted.
¿ì»îÁÖÐÔÏ¢ AWS is integrated with ¿ì»îÁÖÐÔϢ’s single sign-on platform (SSO) for authentication. Users are not allowed to create or log in through local user account created within ¿ì»îÁÖÐÔÏ¢ AWS account. ¿ì»îÁÖÐÔÏ¢ AWS security audit logs (CloudTrails logs) are sent to central security account for auditing purposes if/when required.
Each ¿ì»îÁÖÐÔÏ¢ AWS Account comes pre-configured with four subnets. These subnets are split across two availability zones (AZ, refers to AWS datacenter). Two subnets are labeled ‘public’ – meaning these subnets have access to the internet (outbound), while two subnets are labeled ‘private’ – meaning these subnets have access to campus datacenter network, but not internet access.
From an end user console experience, ¿ì»îÁÖÐÔÏ¢ AWS is identical to an AWS account. However, several key differences are listed below:
- By default, users can use services under the Oregon region. If other regions are required, please contact theÌýIT Help Center.
- Users are not allowed to create local users (IAM user) or to create custom roles or policies. If the default access does not meet the needs, please contact theÌýIT Help Center.
- Users have limited access to network services under AWS. For example, users are not allowed to modify/delete/create VPCs, subnets, internet gateways (IGWs) etc. If the default network configuration does not meet your needs, please contact theÌýIT Help Center.Ìý
- ¿ì»îÁÖÐÔÏ¢ AWS allows for ease of payment and cost tracking.
- Tied to ¿ì»îÁÖÐÔÏ¢'s purchasing department using POs. No P Card or credit card needed.Ìý
- ¿ì»îÁÖÐÔÏ¢ AWS has pre-established security and technical configurations consistent with CSU guidelines.
- ¿ì»îÁÖÐÔÏ¢ AWS users can contact ¿ì»îÁÖÐÔÏ¢ IT to estimate costs or help architect the environment.Ìý
- Connected to ¿ì»îÁÖÐÔÏ¢'s in-campus network.Ìý
- No need to agree to AWS Terms and Conditions.Ìý
Yes! The account can be used as soon as the ¿ì»îÁÖÐÔÏ¢ AWS account is created. Users receive a notification email with their account details. At that point, The ¿ì»îÁÖÐÔÏ¢ AWS account is ready for use. If there are any questions or issues, please contact theÌýIT Help Center.Ìý
.Ìý
Ìý
¿ì»îÁÖÐÔÏ¢ AWS is integrated with ¿ì»îÁÖÐÔÏ¢'s standard procurement process using purchasing orders (POs). During the account creation process, the ¿ì»îÁÖÐÔÏ¢ AWS account is linked to a ¿ì»îÁÖÐÔÏ¢ issued PO. Every month, the respective ¿ì»îÁÖÐÔÏ¢ Accounts Payable department will receive a bill. The respective accounts payable team will charge the PO tied to a particular ¿ì»îÁÖÐÔÏ¢ AWS account.
Yes. Users can view and track their ¿ì»îÁÖÐÔÏ¢ AWS charges directly under their ¿ì»îÁÖÐÔÏ¢ account by going to the ‘Billing’ service. Users are able to create budgets, set-up notifications and run reports.
Ìý
Purchase Order questions should be directed to your department or Contact Purchasing & Contracts Administration at (818) 677-2301 or via email atÌýpurch@csun.eduÌýfor assistance with Purchase Order (PO) creation and processing.
Ìý
Ìý