Skip to content
Identity and access

The federation boundary, pointed at one directory.

IAM Identity Center federates access to AWS accounts and applications from an external identity provider, replacing per-account users with assignments driven by the directory. Our work is federating AWS access to one directory so reviews and offboarding cover it.

Identity Center is where AWS access should resolve to the same directory as everything else. Where it does not, the estate has a second population nobody reviews.

What it is

IAM Identity Center federates access to AWS accounts and applications from an external identity provider, replacing per-account users with assignments driven by the directory.

It is for organizations whose AWS access grew account by account, which is the normal history and the reason offboarding rarely reaches all of it.

identity owner expires one owner recorded, five unaccounted L1 L2 L3 L4

What it does

Federation from your directory

Access derived from the same record as the rest of the estate.

Assignments rather than accounts

Permission sets assigned to groups, so membership drives access.

Where it fits

L1, identity and access. It is the boundary between your directory and everything running in AWS. Where it points at the same identity provider as the rest of the estate, one review covers both. Where it does not, there are two populations and only one gets reviewed.

Where it earns its place

An estate with per-account users

Accounts created during a project and never removed are the usual finding.

An organization consolidating after acquisition

Two AWS estates and two directories is the expensive version of this problem.

Proof

9 in 10

Organizations that had a successful identity-related breach in the last twelve months.

Palo Alto Networks, 2026 Identity Security Landscape, 2,930 respondents.

Questions we get

Do we have to use your directory choice?
No. Whichever is already authoritative. The failure is two directories both claiming to be.

Find out who can reach what.

Fixed scope. The assessment starts at the identity layer: human and non-human access, the accounts nobody owns, and what has to be true before an agent gets one. You get the findings, the ownership gaps, and the order to close them in.