All Services

Security & IAM

AWS IAM Identity Center

AWS IAM Identity Center connects workforce users and groups from an existing identity provider or its identity store to AWS accounts and applications through centralized assignments, permission sets, the access portal, and trusted identity propagation.

Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with AWS IAM Identity Center.

Workforce access design and actual cost

AWS IAM Identity Center Pricing & Access Guide

The pricing answer is short: IAM Identity Center itself has no charge. Budget instead for the directory, applications, logging, and network path around it, and spend the design effort on the identity source and permission sets.

Official AWS sources reviewed 2026-08-29.

How much does AWS IAM Identity Center cost?

AWS states that IAM Identity Center is offered at no extra charge. Real cost sits around it: a managed directory if you run one, the applications and AWS resources users reach, CloudTrail logging, and any networking needed to reach an external identity provider.

AWS IAM Identity Center FAQs

What is IAM Identity Center used for?

It centralizes workforce access to multiple AWS accounts and to supported applications behind one sign-in. Connect an identity source such as an external provider or directory, then grant access through assignments rather than per-account IAM users.

What is AWS IAM Identity Center?

How do permission sets work?

A permission set is a reusable policy definition that Identity Center provisions as an IAM role in every account it is assigned to. Assign permission sets to groups instead of individuals, keep them least-privilege, and edit the permission set to change every account that uses it.

Manage AWS accounts with permission sets

Related AWS services for this plan

  • AWS Identity and Access Management — Permission sets become IAM roles, so IAM policy limits and boundaries still apply in each account.
  • AWS Organizations — Identity Center assigns access across AWS Organizations accounts from the management account.
  • AWS CloudTrail — Audit sign-in and assignment changes in CloudTrail, which is where access review evidence comes from.
  • Amazon Cognito — Use Cognito for customer-facing application identity; Identity Center covers workforce access.

AWS IAM Identity Center pricing and cost programs

Pricing model: No additional core-service charge

On-Demand
Service-specific
Reserved Instances or reserved capacity
Not applicable
Savings Plans
Not applicable
Spot
Not applicable

Billing dimensions: Related directory · Application · CloudTrail, logging, and network services

Programs and modes: Workforce access · Multi-account permissions · Application access

IAM Identity Center has no additional charge for core functionality; integrated services may be billed.

Free Tier: Not applicable — verify current offers

Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.

Official AWS pricing

Official AWS sources reviewed 2026-07-21.

Why implement AWS IAM Identity Center?

  • Centralizes workforce access to multiple AWS accounts and supported applications instead of creating separate IAM users in every account.
  • Uses permission sets to provision controlled IAM roles and short-lived sessions consistently across organization accounts.
  • Supports access portals, federation, group synchronization, trusted identity propagation, and user-attributed CloudTrail activity for supported services.

How to implement AWS IAM Identity Center

  1. Use an organization instance for production and multi-account access, select the home Region intentionally, and connect the authoritative external identity provider or carefully govern the built-in identity store.
  2. Synchronize groups, create job-function permission sets with least-privilege policies and session durations, assign groups rather than individuals to accounts and applications, and delegate administration outside the management account where supported.
  3. Require strong MFA, test console and CLI access, monitor provisioning and CloudTrail activity, define joiner-mover-leaver automation, and regularly review assignments, permission sets, active sessions, and break-glass access.

AWS IAM Identity Center best practices

  • Use the organization instance—AWS identifies it as the best practice and recommends it for production application use—rather than scattered account instances.
  • Assign access through governed groups and narrowly scoped permission sets, shorten sessions for sensitive roles, and minimize workforce access to the Organizations management account.
  • Use phishing-resistant MFA where possible, automate identity deprovisioning, understand that ending a portal session does not instantly end every IAM role session, and monitor anomalous access patterns.

AWS IAM Identity Center use cases and server impact

  • Single sign-on to many AWS accounts
  • Central workforce access to AWS applications
  • Short-lived CLI credentials for engineers

Replaces many custom federation portals and per-account IAM-user processes, while the identity source, permission design, access reviews, session policy, and emergency access remain customer responsibilities.

Official implementation resources

Commonly paired AWS services