Cloudera Docs

Onboarding CDP users and groups for cloud storage (RAZ environments)

If your AWS environment has Fine-grained access control enabled, you should onboard your users using Ranger instead of using IDBroker.

For more information, refer to Ranger policy options for RAZ-enabled AWS environment and Using Ranger to Provide Authorization in CDP.

Parent topic: S3 bucket, and IAM roles and policies for logs, backups, and data storage