AWS IAM Identity Center
(Redirected from Identity store)
Jump to navigation
Jump to search
wikipedia:AWS IAM Identity Center (Jul 2022) [1] (previously AWS Single Sign-On)
Supported identity source:
- External identity provider
- Active Directory
- Identity Center directory (free of charge, default)
- Enable multi-account access to your AWS accounts
- Enable single sign-on access to your AWS applications
- Enable single sign-on access to Amazon EC2 Windows instances
Commands[edit]
aws sso login
aws configure sso
aws sts assume-role
aws sts get-session-token
Only valid for IAM users
Terraform resources[edit]
Related[edit]
- Okta https://www.okta.com/blog/2020/05/how-okta-aws-iam-identity-center-simplifies-admin-and-adds-cli-support/
- JumpCloud
SCIM
protocol, Created by SCIM- Permission sets:
AdministratorAccess, PowerUserAccess
aws_ssoadmin_permission_set
- Maximum session duration, up to 7 days or custom duration.
- AWS access portal: https://d-xxxxxxxxxx.awsapps.com/start
aws sso-admin
- ssoins
AdministratorAccess
arn:aws:sso:::permissionSet
- AWS Verified Access (2023)
- Organization instances of IAM Identity Center
Activities[edit]
- Configure the AWS CLI to use AWS IAM Identity Center. See also: AWS SSO token provider configuration https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-sso.html
- How to use Google Workspace as an external identity provider for AWS IAM Identity Center
- Multi-factor authentication for Identity Center users
See also[edit]
aws sso login, ~/.aws/sso/cache
- AWS SSO:
aws sso
,aws sso login
,aws sso list-accounts
,aws-sso-util, aws sso-admin
- AWS IAM Identity Center:
aws identitystore [ create-user | create-group | list-groups | list-users ]
, Permission sets - AWS IAM Identity Center, AWS SSO,
aws sso
, AWS access portal,aws_ssoadmin_permission_set, arn:aws:sso
- AWS IAM Identity Center,
aws identitystore
, AWS Identity Center directory, SSO - AWS users: AWS IAM users and/or Identity Center users
Advertising: