AWS IAM Identity Center supports one-click multi-Region option for new organization instances

AWS IAM Identity Center now makes it easier to enable multi-Region support when creating a new organization instance. Previously, enabling multi-Region support required multiple steps including creating a customer managed KMS key, configuring key policies, and manually adding Regions. Now, customers creating a new IAM Identity Center instance in supported Regions can enable multi-Region in one click.

When enabling a new organization instance, you can choose from three instance configuration options: single-Region instance, multi-Region instance, or custom instance. The multi-Region instance option automatically creates a customer managed multi-Region KMS key in your account and replicates your instance to an additional Region. This enables resilient AWS account and application access — your workforce can continue to access their AWS accounts even if IAM Identity Center experiences a disruption in the primary Region. The custom instance option lets you configure your Region settings individually, including the ability to use an existing customer managed KMS key from your account.

Instance configuration options are available in 17 enabled-by-default commercial AWS Regions for organization instances of IAM Identity Center. Standard AWS KMS charges apply for the customer managed key created with the multi-Region instance option. IAM Identity Center is provided at no additional cost.

To get started, see the IAM Identity Center User Guide. To learn more about multi-Region support, see Using IAM Identity Center across multiple AWS Regions. To learn more about IAM Identity Center, visit the product detail page.

Categories: general:products/aws-iam-identity-center,marketing:marchitecture/security-identity-and-compliance

Source: Amazon Web Services

Share This Update