New feature

AWS IAM Identity Center makes management of AWS account access optional for new organization instances

AWS IAM Identity Center now allows you to choose whether to enable AWS account access management when creating a new organization instance, reducing the access surface in your environment when account management is not needed.

AWS IAM Identity Center now allows you to decide whether to enable management of AWS account access when you create a new organization instance. This allows you to use IAM Identity Center to manage access to AWS applications only, without the need to manage access to AWS accounts. This feature is available at the time of initial configuration of an IAM Identity Center instance and does not affect existing IAM Identity Center instances. When you choose not to enable management of AWS accounts, IAM Identity Center does not provision its service-linked role into your member accounts, which reduces the access surface in your environment. You can enable account management permissions later through instance settings or the UpdateInstance API. This capability is available in all AWS Regions where IAM Identity Center is available.

Read the original AWS announcement