Access to DIT provided AWS accounts via the AWS console is a 2-step process which is outlined below. Users must first login as an IAM role based on their HR group, and from there they can assume 1 or more IAM roles related to functional tasks. These functional roles may be in multiple AWS accounts.