- Allowing users from one AWS account to access resources in another AWS account
- Authenticating users with multi-factor authentication (MFA)
- Encrypting data at rest and in transit
- Monitoring and recording account activity for compliance auditing