Glossary

    Single Sign-On (SSO)

    Identity & Access

    Single Sign-On (SSO) allows users to authenticate once and gain access to multiple AWS accounts and business applications. In AWS, this is implemented through IAM Identity Center (formerly AWS SSO), which provides a user portal where users can see and access all accounts and applications they are authorized for.

    Key Features

    • Centralized user management with built-in directory or external IdP (Active Directory, Okta)
    • Permission Sets - reusable collections of policies assigned to users/groups per account
    • Multi-account access from a single portal
    • Integration with business applications (Salesforce, Slack, etc.) via SAML
    • Temporary credentials - no long-term access keys needed

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.