AWS IAM Identity Center
Connection
Setup
1
Create an IAM user
Create an IAM user in the
account your
Identity Center instance
runs in, and give it an access key.
2
Allow the actions
Attach a policy allowing the actions under Permissions.
Documentation Index
Fetch the complete documentation index at: /docs/llms.txt
Use this file to discover all available pages before exploring further.
Create an IAM user
Allow the actions
| Setting | Required | Description |
|---|---|---|
| Access key ID | Yes | Access key ID of the IAM user Klef signs in as. |
| Secret access key | Yes | Secret of that access key. Stored encrypted. |
| Region | Yes | Region the Identity Center instance runs in. |
| Role ARN | Role to assume, for an account the key was not issued in. | |
| External ID | External ID the role’s trust policy requires. Stored encrypted. | |
| Instance ARN | Identity Center instance ARN. Leave empty when the key reaches only one instance. |
| Capability | Required | Granted by (any one) |
|---|---|---|
| Read the instance and its permission sets | Yes | sso:ListInstances, sso:ListPermissionSets, sso:DescribePermissionSet, sso:ListAccountsForProvisionedPermissionSet |
| Read account assignments | Yes | sso:ListAccountAssignments |
| Assign and remove permission sets | Yes | sso:CreateAccountAssignment, sso:DeleteAccountAssignment, sso:DescribeAccountAssignmentCreationStatus, sso:DescribeAccountAssignmentDeletionStatus |
| Resolve principals in the identity store | Yes | identitystore:GetUserId, identitystore:DescribeUser |
| Name the organization’s accounts | organizations:ListAccounts |
| Field | Type | Required | Description |
|---|---|---|---|
principalId (Identity store user) | reference, user | Yes | The Identity Center user, by user ID, user name or email. Names the account rather than describing it, so a diff leaves it out. |
permission_sets | grant | Permission sets the user holds, each on one account. One row grants one permission set. | |
permission_sets[] (Permission set on account) | string | Account ID and permission set ARN, separated by |. |
stage active {
# Each entry is one permission set on one account: <account id>|<permission set ARN>.
target aws_identity_center.permission_set_assignment {
principalId = worker.business_email
permission_sets = [
"111122223333|arn:aws:sso:::permissionSet/ssoins-0123456789abcdef/ps-developer0000001",
"444455556666|arn:aws:sso:::permissionSet/ssoins-0123456789abcdef/ps-readonly00000001",
]
}
}
Was this page helpful?