IAM Identity Center (formerly AWS SSO) provides central single sign-on to multiple AWS accounts and business applications, with permissions managed once and applied across your whole organization.
The tell
When a scenario needs one sign-on across many AWS accounts (often with AWS Organizations) and centralized permission sets, that’s IAM Identity Center. It connects to your existing identity source (Active Directory, external IdP) and assigns permission sets per account. Multi-account SSO → Identity Center.
Test yourself
A company with dozens of AWS accounts wants employees to sign in once and get appropriate access to each account, managed centrally. Which service?
- An IAM user in each account
- AWS IAM Identity Center
- A shared access key
- A bucket policy
👉 Click to reveal the answer & explanation
Correct answer: B. IAM Identity Center provides centralized single sign-on and permission sets across many AWS accounts, integrated with Organizations and your IdP. Per-account IAM users (A) don’t scale or centralize; shared keys (C) are insecure; bucket policies (D) control resource access, not SSO.
Related topics
AWS IAM · IAM identity federation · AWS Organizations
Ready to pass the AWS Solutions Architect Associate (SAA-C03)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the SAA-C03 Practice Exams →or try 25 free questions first