Single sign-on access to Amazon Web Services accounts - Amazon IAM Identity Center
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Single sign-on access to Amazon Web Services accounts

You can assign users in your connected directory permissions to the management account or member accounts in your organization in Amazon Organizations based on common job functions. Or you can use custom permissions to meet your specific security requirements. For example, you can grant database administrators broad permissions to Amazon RDS in development accounts but limit their permissions in production accounts. IAM Identity Center configures all the necessary user permissions in your Amazon Web Services accounts automatically.

Note

You might need to grant users or groups permissions to operate in the Amazon Organizations management account. Because it is a highly privileged account, additional security restrictions require you to have the IAMFullAccess policy or equivalent permissions before you can set this up. These additional security restrictions are not required for any of the member accounts in your Amazon organization.