The federation boundary, pointed at one directory.
IAM Identity Center federates access to AWS accounts and applications from an external identity provider, replacing per-account users with assignments driven by the directory. Our work is federating AWS access to one directory so reviews and offboarding cover it.
Identity Center is where AWS access should resolve to the same directory as everything else. Where it does not, the estate has a second population nobody reviews.
What it is
IAM Identity Center federates access to AWS accounts and applications from an external identity provider, replacing per-account users with assignments driven by the directory.
It is for organizations whose AWS access grew account by account, which is the normal history and the reason offboarding rarely reaches all of it.
What it does
Federation from your directory
Access derived from the same record as the rest of the estate.
Assignments rather than accounts
Permission sets assigned to groups, so membership drives access.
Where it fits
L1, identity and access. It is the boundary between your directory and everything running in AWS. Where it points at the same identity provider as the rest of the estate, one review covers both. Where it does not, there are two populations and only one gets reviewed.
What we do with it
Where it earns its place
An estate with per-account users
Accounts created during a project and never removed are the usual finding.
An organization consolidating after acquisition
Two AWS estates and two directories is the expensive version of this problem.
Proof
Organizations that had a successful identity-related breach in the last twelve months.
Palo Alto Networks, 2026 Identity Security Landscape, 2,930 respondents.