View a markdown version of this page

Identity and access management in Quick - Amazon Quick
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Identity and access management in Quick

   Applies to: Enterprise Edition and Standard Edition 
   Intended audience: System administrators and Amazon Quick administrators 

The following topics describe how to set up identity and access for Quick.

Note

In the following Amazon Web Services Regions, Amazon Quick accounts can only use IAM Identity Center for identity and access management:

  • af-south-1 Africa (Cape Town)

  • ap-southeast-3 Asia Pacific (Jakarta)

  • ap-southeast-5 Asia Pacific (Malaysia)

  • eu-south-1 Europe (Milan)

  • eu-south-2 Europe (Spain)

  • eu-central-2 Europe (Zurich)

  • il-central-1 Israel (Tel Aviv)

  • me-central-1 Middle East (UAE)

The following sections help you configure the identity management method of your choice for Quick.

IAM permissions control access to some sections of the Amazon Quick administration console. The following table lists admin actions and whether they require IAM permissions.

Admin action IAM permissions required

Account settings

Yes

Manage assets

Yes

Amazon Q

Yes

Manage subscriptions

No

SPICE capacity

No

Index capacity

Yes

Manage users (view)

No

Manage users > Role groups

Yes

Manage domains

No

Mobile settings

No

Manage IP/VPC restrictions

Yes

Manage VPC connections

Yes

Manage OAuth client applications

Yes

KMS keys

Yes

Amazon resources

Yes

Default access policy

Yes

IAM policy assignments

Yes

Amazon actions

Yes

Extension access

Yes

Custom permissions

Yes

Configure SageMaker

Yes

Brand customization

Yes

Agent customization

Yes

Email customization

Yes

Quick Usage Metrics

Yes

If you have the Amazon Quick admin role, you can perform actions that do not require IAM permissions. To perform actions that require IAM permissions, sign in to the Amazon Web Services Management Console as an IAM principal with the appropriate quicksight:* permissions. You can also perform some admin actions programmatically through the Amazon Quick API. For a list of available API operations, see the Amazon Quick API Reference.