> For the complete documentation index, see [llms.txt](https://mamawhocode.gitbook.io/aws/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://mamawhocode.gitbook.io/aws/services/access-management/iam_identitycenter.md).

# IAM Identity Center (SSO)

## IAM Identity Center (SSO)

{% hint style="info" %}
connect an existing directory or use the built-in Identity Center directory to manage user access to AWS accounts and cloud application.
{% endhint %}

* Centrally managed SSO to access multiple accounts and 3rd-party business applications.
* Integrated with OU and supports SAML 2.0 and AD.
* Centrallized permission and CloudTrail audit.

![](https://rxhl.notion.site/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Fed77bcb7-df22-4eb0-9f44-79b517d5d00a%2FScreen_Shot_2020-09-13_at_2.19.37_PM.png?table=block\&id=8c04d78f-cb73-4bfe-8c6b-077da25ef510\&spaceId=b3a9e1c5-c540-47ac-82b3-9b6937f151ed\&width=1440\&userId=\&cache=v2)

### Related services

* AWS Organization
* AWS IAM

## Trivia

* A <mark style="background-color:yellow;">two-way</mark> trust relationship is needed between AWS Managed Microsoft AD and a self-managed AD for users to sign in with their corporate credentials to AWS services.

## Concepts

* [Permission set](/aws/services/access-management/iam_identitycenter.md): a set of one or more IAM policies assigned to users and groups to define AWS access.
