AWS Identity and Access Management streamlines assignment of IAM roles to workforce users with account access manager
AWS Identity and Access Management introduced account access manager to simplify assigning IAM roles to workforce users via AWS IAM Identity Center, replacing two previous access management approaches.
AWS Identity and Access Management (IAM) has launched account access manager, a new feature designed to simplify the assignment of IAM roles to workforce users. Administrators can now use this tool to assign roles in AWS accounts directly to users and groups managed through AWS IAM Identity Center. The feature consolidates permissions management, enhances user visibility, and provides a unified point for federation, accessible via the AWS IAM console, AWS SDK, and CloudFormation/CDK.
Previously, customers had two main options for granting workforce access to AWS accounts. One approach involved federating users separately into each account and defining narrow permissions using IAM roles within those accounts. The alternative allowed federating users once through IAM Identity Center and managing access centrally by adjusting AWS managed permission sets. The new account access manager bridges these methods by combining the single federation point and user awareness of IAM Identity Center with the flexibility of IAM roles.
The account access manager is available at no additional cost and is enabled by default in all AWS Commercial Regions. This eliminates the need for separate federation setups per account while maintaining granular control over permissions. The feature aims to reduce administrative overhead for organizations managing multi-account AWS environments.
To implement the new feature, administrators can refer to the AWS Identity and Access Management User Guide for detailed instructions. The guide provides step-by-step procedures for assigning roles and configuring access through account access manager, ensuring a smooth transition from existing access management methods.