AWS singlesignon: Updated multi-region identity source requirements
Summary
Clarified that Identity Center directory is now supported for multi-region replication alongside external IdPs, explicitly excluding Active Directory.
Security assessment
The change documents supported identity sources for multi-region deployments, preventing misconfiguration that could cause availability issues. It adds security-adjacent guidance but doesn't address a specific vulnerability.
Evidence
+ * Multi-Region support – If you have replicated IAM Identity Center to additional Regions or plan to do so, you must use an external identity provider or the Identity Center directory as the identity source. Multi-Region support is not available for Active Directory. For more information including other prerequisites, see [Using IAM Identity Center across multiple AWS Regions](./multi-region-iam-identity-center.html).
Diff
diff --git a/singlesignon/latest/userguide/manage-your-identity-source-considerations.md b/singlesignon/latest/userguide/manage-your-identity-source-considerations.md index 962afa347..94814f33b 100644 --- a//singlesignon/latest/userguide/manage-your-identity-source-considerations.md +++ b//singlesignon/latest/userguide/manage-your-identity-source-considerations.md @@ -45,0 +46,2 @@ If you choose to not use Active Directory, you must create your users and groups + * Multi-Region support – If you have replicated IAM Identity Center to additional Regions or plan to do so, you must use an external identity provider or the Identity Center directory as the identity source. Multi-Region support is not available for Active Directory. For more information including other prerequisites, see [Using IAM Identity Center across multiple AWS Regions](./multi-region-iam-identity-center.html). + @@ -92,2 +93,0 @@ You will not be able to revoke user sessions from the IAM Identity Center consol - * Multi-Region support – If you have replicated IAM Identity Center to additional Regions or plan to do so, you must use an external identity provider as the identity source. For more information including other prerequisites, see [Using IAM Identity Center across multiple AWS Regions](./multi-region-iam-identity-center.html). - @@ -134 +134 @@ If you change your identity source from an external IdP to Active Directory, or - * Multi-Region support – If you have replicated IAM Identity Center to additional Regions or plan to do so, you must use an external identity provider as the identity source. For more information including other prerequisites, see [Using IAM Identity Center across multiple AWS Regions](./multi-region-iam-identity-center.html). + * Multi-Region support – If you have replicated IAM Identity Center to additional Regions or plan to do so, you must use an external identity provider or the Identity Center directory as the identity source. Multi-Region support is not available for Active Directory. For more information including other prerequisites, see [Using IAM Identity Center across multiple AWS Regions](./multi-region-iam-identity-center.html).