Mount Amazon S3 as a Windows Drive with TntDrive Using Temporary AWS STS AssumeRole Credentials
TntDrive
Bringing the Cloud Closer
 
Follow

Mount Amazon S3 with AWS STS AssumeRole Credentials

With the Amazon S3 via AssumeRole account type, TntDrive calls AWS Security Token Service (AWS STS) to obtain temporary credentials for an IAM role and mount Amazon S3 buckets as Windows drives.

TntDrive signs the AssumeRole request with credentials from an existing source account. The source principal must be allowed to assume the target role, and the role's trust policy must trust that principal.

AWS STS returns a temporary access key ID, secret access key, and session token. TntDrive keeps these credentials in memory and refreshes them automatically when fewer than five minutes remain before expiration.

TntDrive generates the role session name automatically and uses the default AWS role session duration of 3,600 seconds.

Prepare the IAM role and source account

  • Add the source account to TntDrive before you create the AssumeRole account. TntDrive uses the source account credentials to sign the AWS STS request.
  • Configure the target role's trust policy to trust the source principal.
  • For cross-account access, allow the source principal to call sts:AssumeRole for the target role ARN.
  • Grant the target role only the Amazon S3 permissions required for the buckets and operations that TntDrive will use.
  • For AWS GovCloud (US), select Amazon S3 GovCloud via AssumeRole and use a source account configured for AWS GovCloud (US).

Add an Amazon S3 AssumeRole account to TntDrive

  1. Start TntDrive Dashboard and choose Accounts > Add new account...

    TntDrive Accounts menu with Add new account selected
    Choose Accounts > Add new account.
  2. The Add New Account dialog will open.

    Add an Amazon S3 via AssumeRole account in TntDrive
    Add New Amazon S3 via AssumeRole Account dialog
  3. Enter a descriptive account name.

  4. Choose Amazon S3 via AssumeRole as the account type.

  5. Enter the Role ARN, for example arn:aws:iam::123456789012:role/TntDriveS3Access.

  6. Enter the External ID only if it is required by the target role's trust policy. Use the exact value supplied by the role owner; otherwise, leave this field empty.

  7. Select the Source Account whose credentials TntDrive should use to send the AssumeRole request.

  8. Keep Use secure transfer (SSL/TLS) enabled.

  9. Click Add new account.

You can now add a new mapped drive and select this account. TntDrive will obtain and refresh temporary credentials automatically.

Fully Functional Free Trial
Powered by Amazon Web Services
Social Connection
 
People like TntDrive!
People like us
Related Products
TntDrive is developed by Netsdk Software FZE and is not affiliated with, endorsed by, or sponsored by Amazon or AWS. Amazon S3 and Amazon S3 Glacier are trademarks of Amazon.com, Inc. or its affiliates.
Copyright © 2008-2026 Netsdk Software FZE. All rights reserved.  Terms of Use.  Privacy Policy.  CS Browser.  Prevent RDP Brute-Force.