AWS Security ChangesHomeSearch

AWS singlesignon: Clarified ACS URL requirements for Identity Center directory

Service: singlesignon · 2026-07-29 · Documentation low

File: singlesignon/latest/userguide/multi-region-iam-identity-center.md

Summary

Added exception for Identity Center directory users from ACS URL requirements

Security assessment

Prevents unnecessary security configuration for specific identity sources, reducing potential misconfiguration risks

Evidence

+This prerequisite does not apply when using the Identity Center directory as the identity source.

Diff

diff --git a/singlesignon/latest/userguide/multi-region-iam-identity-center.md b/singlesignon/latest/userguide/multi-region-iam-identity-center.md
index 8a2c41f61..cf88e8600 100644
--- a//singlesignon/latest/userguide/multi-region-iam-identity-center.md
+++ b//singlesignon/latest/userguide/multi-region-iam-identity-center.md
@@ -32 +32 @@ Before you replicate your IAM Identity Center instance, ensure the following req
-  * **Identity source** \- Your IAM Identity Center instance must be connected to an external identity provider (IdP), such as [Okta](https://www.okta.com/). Multi-Region support is not available for instances that use [Active Directory](./gs-ad.html) or the [Identity Center directory](./quick-start-default-idc.html) as the identity source. 
+  * **Identity source** \- Your IAM Identity Center instance must be connected to an external identity provider (IdP), such as [Okta](https://www.okta.com/), or use the [Identity Center directory](./quick-start-default-idc.html) as the identity source. Multi-Region support is not available for instances that use [Active Directory](./gs-ad.html) as the identity source. 
@@ -44 +44 @@ Before you replicate your IAM Identity Center instance, ensure the following req
-  * **External IdP compatibility** \- To fully take advantage of multi-Region support, the external IdP must support multiple assertion consumer service (ACS) URLs. This is a SAML feature that is supported by IdPs such as Okta, Microsoft Entra ID, PingFederate, PingOne, and JumpCloud.
+  * **External IdP compatibility (external identity providers only)** \- If you use an external identity provider, the IdP must support multiple assertion consumer service (ACS) URLs to fully take advantage of multi-Region support. This is a SAML feature that is supported by IdPs such as Okta, Microsoft Entra ID, PingFederate, PingOne, and JumpCloud.
@@ -46 +46 @@ Before you replicate your IAM Identity Center instance, ensure the following req
-If you use an IdP that doesn't support multiple ACS URLs, such as Google Workspace, we recommend that you work with your IdP vendor to enable this feature. For options that are available without multiple ACS URLs, see [Using AWS managed applications without multiple ACS URLs](./multi-region-workforce-access.html#aws-app-use-without-multiple-acs-urls) and [AWS account access resiliency without multiple ACS URLs](./multi-region-failover.html#account-access-resiliency-without-multiple-acs-url). 
+If you use an IdP that doesn't support multiple ACS URLs, such as Google Workspace, we recommend that you work with your IdP vendor to enable this feature. This prerequisite does not apply when using the Identity Center directory as the identity source. For options that are available without multiple ACS URLs, see [Using AWS managed applications without multiple ACS URLs](./multi-region-workforce-access.html#aws-app-use-without-multiple-acs-urls) and [AWS account access resiliency without multiple ACS URLs](./multi-region-failover.html#account-access-resiliency-without-multiple-acs-url).