AWS Identity and Access Management (IAM) launched account access manager, a feature that streamlines assignment of IAM roles to workforce users. Administrators use account access manager to assign the IAM roles in their AWS accounts to the workforce users and groups in AWS IAM Identity Center. The feature brings together permissions management flexibility, user awareness, and a single point of federation. It is accessible through the AWS IAM console, the AWS SDK, and CloudFormation/CDK.
Previously, customers granting workforce access to AWS accounts could use one of two alternative access management approaches. They could federate users separately into each AWS account and define user permissions narrowly using the IAM roles in each AWS account. Alternatively, they could federate users once through IAM Identity Center, and tailor and manage their access centrally by adjusting and provisioning AWS managed permission sets. The newly released account access manager offers a solution for customers who want the single federation point and user awareness of IAM Identity Center together with the flexibility of IAM roles.
Account access manager is provided at no additional cost and available in all AWS Commercial Regions enabled by default. To learn more and get started, visit the AWS Identity and Access Management User Guide.
Categories:
Source: Amazon Web Services


