Security, Identity, and Compliance
CoreAWS IAM Identity Center
Central workforce access to multiple AWS accounts and supported applications using an identity source and permission assignments.
Key points
- Identity Center issues temporary account access through assigned permission sets rather than creating an IAM user in every account.
- It can use its identity store or integrate with an external workforce identity source.
- Account assignments grant role-based access; Organizations and SCPs provide separate account governance boundaries.
Best-known use cases
- Give employees centralized access to many AWS accounts.
- Federate workforce identities into business applications.
What candidates often confuse it with
- Identity Center serves workforce access; Cognito serves application end users.
- Identity Center assigns access; Organizations groups accounts and applies SCP guardrails.
Key takeaway
Choose IAM Identity Center for centralized temporary workforce access across accounts.
Related services
- IAM
- AWS Organizations
- AWS Directory Service
Relevant exam tasks
- D1.1