Glossary

    IAM Identity Center

    Identity & Access

    IAM Identity Center (formerly AWS SSO) is the recommended way to manage human access to AWS accounts and business applications. It provides a single sign-on experience across all your AWS accounts in an organization.

    Key Features

    • Centralized Access: one place to manage access to all AWS accounts
    • Permission Sets: reusable sets of IAM policies assigned to users/groups for specific accounts
    • Identity Sources: built-in directory, Active Directory (AD Connector or AWS Managed AD), or external IdP (Okta, Azure AD, Ping)
    • MFA: built-in MFA with WebAuthn/FIDO2, authenticator apps, and RADIUS
    • Application Assignments: SSO access to SAML 2.0 applications (Salesforce, Slack, etc.)

    Why Use It

    • Eliminates IAM users - no more long-term credentials for humans
    • Centralized audit trail of who accessed which account
    • Automatic credential rotation (temporary credentials via STS)
    • Works with AWS Organizations for multi-account management

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.