AWS Certified CloudOps Engineer - Associate

IAM Identity Center

How one identity source and a handful of permission sets replace per-account IAM users across an organization: instance types, assignments, the IAM roles Identity Center creates for you, session durations, and attribute-based access control.

Intermediate 25 minutes 7 Learning Objectives
  1. Explain what problem IAM Identity Center solves that per-account IAM users cannot
  2. Distinguish an organization instance from an account instance and state what each can manage
  3. Describe the 3 identity source options and the effect of choosing an external provider
  4. Trace what an assignment creates in a target account and what happens when a permission set changes
  5. Differentiate the permission set session duration from the AWS access portal session duration
  6. Configure attribute-based access control so one permission set serves several teams
  7. Choose between IAM Identity Center, federation with IAM, and Cognito identity pools for a stated scenario