aws AWS What's New ·

AWS IAM Identity Center makes AWS account access management optional for new instances

securityawsengineeraws-iam
feature

AWS IAM Identity Center now allows new organization instances to optionally manage AWS account access, enabling a focus on managing access to AWS applications only. This reduces the access surface by not provisioning service-linked roles into member accounts when account management is disabled. The feature is available at initial instance configuration and does not impact existing instances.

  • Optional AWS account access management for new IAM Identity Center instances
  • Impact and availability of the new IAM Identity Center feature
Features (1)
  • Optional AWS account access management for new IAM Identity Center instances

    New AWS IAM Identity Center organization instances can now choose not to enable management of AWS account access, allowing users to manage access to AWS applications exclusively. This change avoids provisioning service-linked roles into member accounts, thereby reducing the environment's attack surface. Account management can be enabled later via instance settings or the UpdateInstance API.

Notes (1)
  • Impact and availability of the new IAM Identity Center feature

    This feature is available at the time of initial configuration for new IAM Identity Center instances and does not affect existing instances. It is available in all AWS Regions where IAM Identity Center is supported.

Read the original announcement →

https://aws.amazon.com/about-aws/whats-new/2026/08/aws-identity-center-accounts-optional/

Related releases