AWS IAM streamlines IAM role assignment to workforce users with account access manager
AWS IAM introduces account access manager, simplifying IAM role assignment. It provides a single federation point and user awareness through IAM Identity Center.
AWS Identity and Access Management (IAM) has launched account access manager, a feature that streamlines the assignment of IAM roles to workforce users. Administrators can use account access manager to assign IAM roles in their AWS accounts to workforce users and groups in AWS IAM Identity Center. This feature combines permissions management flexibility, user awareness, and a single point of federation. It is accessible through the AWS IAM console, AWS SDK, and CloudFormation/CDK. Previously, customers granting workforce access to AWS accounts could use one of two alternative access management approaches. They could federate users separately into each AWS account and define user permissions narrowly using IAM roles in each AWS account. Alternatively, they could federate users once through IAM Identity Center and tailor and manage their access centrally by adjusting and provisioning AWS managed permission sets. The newly released account access manager offers a solution for customers who want the single federation point and user awareness of IAM Identity Center along with the flexibility of IAM roles. Account access manager is provided at no additional cost and is available in all AWS Commercial Regions enabled by default.