aws AWS What's New ·

AWS IAM Identity Center: Optional account access management for new instances

securityawsengineeraws-iam
feature

AWS IAM Identity Center now allows administrators to choose whether to manage AWS account access when creating a new organization instance. This decoupling enables users to manage access to AWS applications independently of account access, simplifying setup and reducing the security surface for organizations not requiring direct account access via Identity Center. The feature is available for new instances and can be enabled later, with account management now being optional from the outset.

  • IAM Identity Center: Optional AWS account access management for new instances
  • Benefits for application owners and end users
  • Availability and existing instances
Features (1)
  • IAM Identity Center: Optional AWS account access management for new instances

    When creating a new AWS IAM Identity Center instance, administrators can now choose to not enable the management of AWS account access. This allows for managing only AWS application access, reducing the security surface by not provisioning service-linked roles into member accounts. Account management can be enabled later via instance settings or API.

Notes (2)
  • Benefits for application owners and end users

    IAM Identity Center simplifies workforce identity management to AWS applications, providing single sign-on and a consistent authentication experience. This release enhances flexibility by making AWS account access management optional.

  • Availability and existing instances

    This new capability is available in all AWS Regions where IAM Identity Center is offered and applies only to new IAM Identity Center instances. Existing instances are not affected by this change.

Read the original announcement →

https://aws.amazon.com/about-aws/whats-new/2026/08/aws-identity-center-accounts-optional/

Related releases