All Services
Security & IAM
AWS IAM Identity Center
AWS IAM Identity Center connects workforce users and groups from an existing identity provider or its identity store to AWS accounts and applications through centralized assignments, permission sets, the access portal, and trusted identity propagation.
Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with AWS IAM Identity Center.
Workforce access design and actual cost
AWS IAM Identity Center Pricing & Access Guide
The pricing answer is short: IAM Identity Center itself has no charge. Budget instead for the directory, applications, logging, and network path around it, and spend the design effort on the identity source and permission sets.
Official AWS sources reviewed 2026-08-29.
How much does AWS IAM Identity Center cost?
AWS states that IAM Identity Center is offered at no extra charge. Real cost sits around it: a managed directory if you run one, the applications and AWS resources users reach, CloudTrail logging, and any networking needed to reach an external identity provider.
AWS IAM Identity Center FAQs
What is IAM Identity Center used for?
It centralizes workforce access to multiple AWS accounts and to supported applications behind one sign-in. Connect an identity source such as an external provider or directory, then grant access through assignments rather than per-account IAM users.
What is AWS IAM Identity Center?
How do permission sets work?
A permission set is a reusable policy definition that Identity Center provisions as an IAM role in every account it is assigned to. Assign permission sets to groups instead of individuals, keep them least-privilege, and edit the permission set to change every account that uses it.
Manage AWS accounts with permission sets
Related AWS services for this plan
- AWS Identity and Access Management — Permission sets become IAM roles, so IAM policy limits and boundaries still apply in each account.
- AWS Organizations — Identity Center assigns access across AWS Organizations accounts from the management account.
- AWS CloudTrail — Audit sign-in and assignment changes in CloudTrail, which is where access review evidence comes from.
- Amazon Cognito — Use Cognito for customer-facing application identity; Identity Center covers workforce access.
AWS IAM Identity Center pricing and cost programs
Pricing model: No additional core-service charge
- On-Demand
- Service-specific
- Reserved Instances or reserved capacity
- Not applicable
- Savings Plans
- Not applicable
- Spot
- Not applicable
Billing dimensions: Related directory · Application · CloudTrail, logging, and network services
Programs and modes: Workforce access · Multi-account permissions · Application access
IAM Identity Center has no additional charge for core functionality; integrated services may be billed.
Free Tier: Not applicable — verify current offers
Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.
Official AWS pricing
Official AWS sources reviewed 2026-07-21.
Why implement AWS IAM Identity Center?
- Centralizes workforce access to multiple AWS accounts and supported applications instead of creating separate IAM users in every account.
- Uses permission sets to provision controlled IAM roles and short-lived sessions consistently across organization accounts.
- Supports access portals, federation, group synchronization, trusted identity propagation, and user-attributed CloudTrail activity for supported services.
How to implement AWS IAM Identity Center
- Use an organization instance for production and multi-account access, select the home Region intentionally, and connect the authoritative external identity provider or carefully govern the built-in identity store.
- Synchronize groups, create job-function permission sets with least-privilege policies and session durations, assign groups rather than individuals to accounts and applications, and delegate administration outside the management account where supported.
- Require strong MFA, test console and CLI access, monitor provisioning and CloudTrail activity, define joiner-mover-leaver automation, and regularly review assignments, permission sets, active sessions, and break-glass access.
AWS IAM Identity Center best practices
- Use the organization instance—AWS identifies it as the best practice and recommends it for production application use—rather than scattered account instances.
- Assign access through governed groups and narrowly scoped permission sets, shorten sessions for sensitive roles, and minimize workforce access to the Organizations management account.
- Use phishing-resistant MFA where possible, automate identity deprovisioning, understand that ending a portal session does not instantly end every IAM role session, and monitor anomalous access patterns.
AWS IAM Identity Center use cases and server impact
- Single sign-on to many AWS accounts
- Central workforce access to AWS applications
- Short-lived CLI credentials for engineers
Replaces many custom federation portals and per-account IAM-user processes, while the identity source, permission design, access reviews, session policy, and emergency access remain customer responsibilities.
Official implementation resources
Commonly paired AWS services