IAM Identity Center extends multi-Region support to Identity Center directory
IAM Identity Center now supports multi-Region replication for instances using the Identity Center directory, enhancing resilience and deployment flexibility across AWS Regions.
IAM Identity Center helps configure single sign-on for your workforce to AWS accounts and applications. You can now replicate IAM Identity Center from the primary AWS Region where you first enabled it to additional Regions of your choice when using Identity Center directory as your identity source. This extends multi-Region support, previously available for Identity Center organization instances connected to external identity providers, to instances that use the Identity Center directory to manage and authenticate their workforce. This feature enhances resilience of user access to AWS accounts and helps you deploy AWS applications in AWS Regions that best align with your business needs such as application data residency and proximity to users. When enabled, IAM Identity Center automatically replicates identities, entitlements, and other information from the primary Region to additional Regions. If IAM Identity Center is affected by a disruption in the primary Region, users continue to access their AWS accounts using the already provisioned entitlements in the additional Regions. AWS application administrators can use the standard application deployment workflow to deploy applications in an additional Region while continuing to administer IAM Identity Center in the primary Region. IAM Identity Center multi-Region support is currently available in the 17 default-enabled commercial AWS Regions for IAM Identity Center organization instances. The IAM Identity Center organization instance must be configured with a multi-Region customer managed KMS key (CMK). Standard AWS KMS charges apply for storing and using CMKs. IAM Identity Center is provided at no additional cost.