Getting started with IAM Identity Center - Amazon IAM Identity Center
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Getting started with IAM Identity Center

The following outlines how you can get started with IAM Identity Center.

  1. Enable IAM Identity Center

    When you enable IAM Identity Center, you choose between two types of IAM Identity Center instances. These types are: organization instances (recommended) and account instances. To learn more about the different capabilities of these instance types, see organization and account instances of IAM Identity Center.

    Note

    After IAM Identity Center is enabled, you can sign in and open the IAM Identity Center console by doing either of the following:

    • Organization instance - Sign in to Amazon using credentials with administrative permissions in the management account.

    • Account instance - Sign in to Amazon using credentials with administrative permissions in the Amazon Web Services account where IAM Identity Center is enabled.

  2. Connect your identity source to IAM Identity Center

    In IAM Identity Center console, confirm the identity source that you want to use. See the following for identity sources:

  3. Set up user access to Amazon Web Services accounts (organization instance only)

    If you’re using an organization instance of IAM Identity Center, you can assign user or group access to Amazon Web Services accounts, using permission sets to grant your users access to Amazon Web Services accounts and resources.

  4. Set up user access to applications

    With IAM Identity Center, you can grant users access to two types of applications:

    1. Amazon managed applications

    2. Customer managed applications

  5. Provide your users with sign-in instructions for the Amazon Web Services access portal

    The Amazon Web Services access portal is a web portal that provides your users with seamless access to all their assigned applications, Amazon Web Services accounts, or both. New users in IAM Identity Center must activate their user credentials before they can sign in to the Amazon Web Services access portal.

    For information about how to sign in to the Amazon Web Services access portal, see Sign in to the Amazon Web Services access portal in the Amazon Sign-In User Guide. To learn about the sign-in process for the Amazon Web Services access portal, see Signing in to the Amazon Web Services access portal.