Amazon IAM Identity Center
AWS IAM Identity Center (successor to AWS Single Sign-On) is where you create, or connect, your workforce identities in AWS once and manage access centrally across your AWS organization. You can create user identities directly in IAM Identity Center, or bring them from Microsoft Active Directory, and then use IAM Identity Center to manage user access to AWS accounts and business applications with single sign-on.
APIs
AWS IAM Identity Center SSO Admin API
Manages permission sets, account assignments, instances, and SSO configurations for centralized identity and access management across AWS accounts and organizations.
AWS IAM Identity Center Identity Store API
Manages users, groups, and group memberships in the IAM Identity Center identity store, enabling programmatic provisioning of workforce identities.
Features
Create and manage workforce user identities directly or connect from an external identity provider.
Enable employees to sign in once and access all assigned AWS accounts and business applications.
Manage access to multiple AWS accounts from a single place using permission sets.
Connect Microsoft Active Directory, Okta, Azure AD, and other SAML 2.0 identity providers.
Define and reuse permission policies that can be assigned to users across multiple AWS accounts.
Automatically provision and de-provision users and groups using SCIM 2.0.
Use Cases
Enable employees to access all AWS accounts and business apps with a single set of credentials.
Manage access to dozens or hundreds of AWS accounts from a single control plane.
Grant temporary elevated access to AWS accounts without permanent permissions.
Centralize access logging and produce audit reports for security compliance reviews.
Semantic Vocabularies
API Governance Rules
JSON Structure
Sso Admin Attach Customer Managed Policy Reference To Permission Set Request Structure
3 properties
JSON STRUCTURESso Admin Attach Customer Managed Policy Reference To Permission Set Response Structure
0 properties
JSON STRUCTURESso Admin Create Instance Access Control Attribute Configuration Request Structure
2 properties
JSON STRUCTURESso Admin Create Instance Access Control Attribute Configuration Response Structure
0 properties
JSON STRUCTURESso Admin Delete Instance Access Control Attribute Configuration Request Structure
1 properties
JSON STRUCTURESso Admin Delete Instance Access Control Attribute Configuration Response Structure
0 properties
JSON STRUCTURESso Admin Delete Permissions Boundary From Permission Set Request Structure
2 properties
JSON STRUCTURESso Admin Delete Permissions Boundary From Permission Set Response Structure
0 properties
JSON STRUCTURESso Admin Describe Account Assignment Creation Status Response Structure
1 properties
JSON STRUCTURESso Admin Describe Account Assignment Deletion Status Response Structure
1 properties
JSON STRUCTURESso Admin Describe Instance Access Control Attribute Configuration Request Structure
1 properties
JSON STRUCTURESso Admin Describe Instance Access Control Attribute Configuration Response Structure
3 properties
JSON STRUCTURESso Admin Describe Permission Set Provisioning Status Response Structure
1 properties
JSON STRUCTURESso Admin Detach Customer Managed Policy Reference From Permission Set Request Structure
3 properties
JSON STRUCTURESso Admin Detach Customer Managed Policy Reference From Permission Set Response Structure
0 properties
JSON STRUCTURESso Admin Get Permissions Boundary For Permission Set Response Structure
1 properties
JSON STRUCTURESso Admin Instance Access Control Attribute Configuration Status Structure
0 properties
JSON STRUCTURESso Admin List Accounts For Provisioned Permission Set Request Structure
5 properties
JSON STRUCTURESso Admin List Accounts For Provisioned Permission Set Response Structure
2 properties
JSON STRUCTURESso Admin List Customer Managed Policy References In Permission Set Request Structure
4 properties
JSON STRUCTURESso Admin List Customer Managed Policy References In Permission Set Response Structure
2 properties
JSON STRUCTURESso Admin List Permission Sets Provisioned To Account Response Structure
2 properties
JSON STRUCTURESso Admin Update Instance Access Control Attribute Configuration Request Structure
2 properties
JSON STRUCTURESso Admin Update Instance Access Control Attribute Configuration Response Structure
0 properties
JSON STRUCTUREExample Payloads
Identitystore Addresses Example
EXAMPLEIdentitystore Emails Example
EXAMPLEIdentitystore Filters Example
EXAMPLEIdentitystore Group Ids Example
EXAMPLEIdentitystore Groups Example
EXAMPLEIdentitystore Users Example
EXAMPLESso Admin Account List Example
EXAMPLESso Admin Attach Customer Managed Policy Reference To Permission Set Request Example
3 fields
EXAMPLESso Admin Describe Instance Access Control Attribute Configuration Response Example
3 fields
EXAMPLESso Admin Detach Customer Managed Policy Reference From Permission Set Request Example
3 fields
EXAMPLESso Admin Instance List Example
EXAMPLESso Admin List Customer Managed Policy References In Permission Set Request Example
4 fields
EXAMPLESso Admin List Customer Managed Policy References In Permission Set Response Example
2 fields
EXAMPLE