AWS Certified CloudOps Engineer - Associate
IAM Identity Center
How one identity source and a handful of permission sets replace per-account IAM users across an organization: instance types, assignments, the IAM roles Identity Center creates for you, session durations, and attribute-based access control.
Intermediate 25 minutes 7 Learning Objectives
- Explain what problem IAM Identity Center solves that per-account IAM users cannot
- Distinguish an organization instance from an account instance and state what each can manage
- Describe the 3 identity source options and the effect of choosing an external provider
- Trace what an assignment creates in a target account and what happens when a permission set changes
- Differentiate the permission set session duration from the AWS access portal session duration
- Configure attribute-based access control so one permission set serves several teams
- Choose between IAM Identity Center, federation with IAM, and Cognito identity pools for a stated scenario
