AWS singlesignon: Enhanced IAM Identity Center access management documentation
Summary
Restructured content to emphasize centralized permission management using account access manager and permission sets.
Security assessment
The change documents centralized permission management features, which is a security best practice for enforcing least privilege across AWS accounts.
Evidence
+ * You can also use IAM Identity Center permission sets to centrally create permissions for common job functions such as admin, provision them across AWS accounts, and assign them to users and groups. This optional feature is available only for organization instances of IAM Identity Center.
Diff
diff --git a/singlesignon/latest/userguide/what-is.md b/singlesignon/latest/userguide/what-is.md index d86888ae0..5f2baa117 100644 --- a//singlesignon/latest/userguide/what-is.md +++ b//singlesignon/latest/userguide/what-is.md @@ -44 +44 @@ With trusted identity propagation, AWS managed applications such as Amazon Quick -One place to assign permissions to multiple AWS accounts** +One point of federation to simplify user access to AWS** @@ -47 +47 @@ One place to assign permissions to multiple AWS accounts** -With multi-account permissions, IAM Identity Center provides a single place for you to assign permissions to groups of users in multiple AWS accounts. You can create permissions based on common job functions or define custom permissions that meet your security needs. You can then assign those permissions to workforce users to control their access to specific AWS accounts. +By providing one point of federation, IAM Identity Center reduces the administrative effort required to use multiple AWS managed applications and AWS accounts. With IAM Identity Center, you only federate once, and you have only one certificate to manage when using a [`SAML 2.0`](https://wiki.oasis-open.org/security) identity provider. IAM Identity Center provides AWS managed applications with a common view of users and groups for trusted identity propagation use cases, or when users share access to AWS resources with other people. @@ -49 +49 @@ With multi-account permissions, IAM Identity Center provides a single place for -This optional feature is available only for [organization instances](./organization-instances-identity-center.html) of IAM Identity Center. +For information about how to configure commonly used identity providers to work with IAM Identity Center, see [IAM Identity Center identity source tutorials](./tutorials.html). If you don’t have an existing identity provider, you can [create and manage users directly in IAM Identity Center](./quick-start-default-idc.html). @@ -53 +53,8 @@ This optional feature is available only for [organization instances](./organizat -One point of federation to simplify user access to AWS** +Ability to manage workforce access to multiple AWS accounts** + + +IAM Identity Center gives you options to manage centrally your workforce access to AWS accounts: + + * Your teams can create their IAM roles in AWS accounts and centrally manage role assignments to IAM Identity Center users and groups using the IAM [account access manager](https://docs.aws.amazon.com/IAM/latest/UserGuide/account-access-manager.html) feature. See [Why use account access manager](https://docs.aws.amazon.com/IAM/latest/UserGuide/account-access-manager.html#why-use-account-access-manager) in the _IAM User Guide_ for more information. + + * You can also use IAM Identity Center permission sets to centrally create permissions for common job functions such as admin, provision them across AWS accounts, and assign them to users and groups. This optional feature is available only for organization instances of IAM Identity Center. @@ -56 +62,0 @@ One point of federation to simplify user access to AWS** -By providing one point of federation, IAM Identity Center reduces the administrative effort required to use multiple AWS managed applications and AWS accounts. With IAM Identity Center, you only federate once, and you have only one certificate to manage when using a [`SAML 2.0`](https://wiki.oasis-open.org/security) identity provider. IAM Identity Center provides AWS managed applications with a common view of users and groups for trusted identity propagation use cases, or when users share access to AWS resources with other people. @@ -58 +63,0 @@ By providing one point of federation, IAM Identity Center reduces the administra -For information about how to configure commonly used identity providers to work with IAM Identity Center, see [IAM Identity Center identity source tutorials](./tutorials.html). If you don’t have an existing identity provider, you can [create and manage users directly in IAM Identity Center](./quick-start-default-idc.html).