AWS Security ChangesHomeSearch

AWS singlesignon: Clarified external IdP dependencies in failover documentation

Service: singlesignon · 2026-07-29 · Documentation medium

File: singlesignon/latest/userguide/multi-region-failover.md

Summary

Refined failover guidance to explicitly state external IdP requirements and added a note about Identity Center directory limitations.

Security assessment

The change improves documentation about break-glass access dependencies and failover procedures, hardening operational security. It clarifies identity source requirements but doesn't fix a vulnerability.

Evidence

+This section applies only to instances that use an external identity provider (IdP). If you use the Identity Center directory as your identity source, this limitation does not apply.

Diff

diff --git a/singlesignon/latest/userguide/multi-region-failover.md b/singlesignon/latest/userguide/multi-region-failover.md
index 5f7ae2ca3..8ff9d8dd4 100644
--- a//singlesignon/latest/userguide/multi-region-failover.md
+++ b//singlesignon/latest/userguide/multi-region-failover.md
@@ -15 +15 @@ If your IAM Identity Center instance experiences a disruption in the primary Reg
-We recommend that you communicate the AWS access portal endpoints in additional Regions and the external IdP setup (such as bookmark apps for the additional Regions) to your workforce as soon as you complete the setup in [Replicate IAM Identity Center to an additional Region](./replicate-to-additional-region.html). This will enable them to be ready for failover to an additional Region if needed. 
+We recommend that you communicate the AWS access portal endpoints in additional Regions to your workforce as soon as you complete the setup in [Replicate IAM Identity Center to an additional Region](./replicate-to-additional-region.html). If you use an external identity provider, also communicate the IdP setup (such as bookmark apps for the additional Regions). This will enable them to be ready for failover to an additional Region if needed. 
@@ -21 +21 @@ Similarly, we recommend that AWS CLI users create [AWS CLI profiles](https://doc
-Continuity of access to AWS accounts also depends on the health of your external IdP and permissions such as permission set assignments and group memberships being provisioned and replicated before a service disruption. We recommend your organization also set up [AWS break-glass access](https://docs.aws.amazon.com/wellarchitected/latest/devops-guidance/ag.sad.5-implement-break-glass-procedures.html) to maintain AWS access to a small group of privileged users when the external IdP has a service disruption. [Emergency access](./emergency-access.html) is a similar option that avoids using IAM users, but it too depends on the external IdP. 
+Continuity of access to AWS accounts depends on permissions such as permission set assignments and group memberships being provisioned and replicated before a service disruption. If you use an external identity provider, continuity also depends on the health of your external IdP. We recommend your organization also set up [AWS break-glass access](https://docs.aws.amazon.com/wellarchitected/latest/devops-guidance/ag.sad.5-implement-break-glass-procedures.html) to maintain AWS access to a small group of privileged users when the identity source has a service disruption. [Emergency access](./emergency-access.html) is a similar option that requires an external IdP. 
@@ -24,0 +25,4 @@ Continuity of access to AWS accounts also depends on the health of your external
+###### Note
+
+This section applies only to instances that use an external identity provider (IdP). If you use the Identity Center directory as your identity source, this limitation does not apply.
+