Glossary

    Identity Federation

    Identity & Access

    Identity Federation lets users from outside AWS (corporate Active Directory, Google, Okta, GitHub) access AWS resources without creating individual IAM users. Instead, external identities are mapped to IAM roles via federation protocols.

    Federation Methods

    • IAM Identity Center (SSO): AWS recommended; centralized access management for multiple accounts with built-in user portal
    • SAML 2.0: for enterprise identity providers (Active Directory, Okta, OneLogin)
    • OIDC (OpenID Connect): for web/mobile apps and CI/CD (GitHub Actions, GitLab, EKS pod identity)
    • Amazon Cognito: for customer-facing applications with social login

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.