# AWS IAM Identity Center

> AWS IAM Identity Center (formerly AWS SSO) gives people single sign-on access to multiple AWS accounts and applications with permission sets.

- Source: https://www.itwonderlab.com/aws-iam-identity-center/
- Published: 2026-02-12
- Updated: 2026-02-12
- Author: Javier Ruiz Jiménez (https://www.javierruizjimenez.com/)
- Site: IT Wonder Lab (https://www.itwonderlab.com/)

---

**IAM Identity Center** is the recommended way to give people access to AWS. Users and groups come from its own directory or from an external identity provider (Microsoft Entra ID, Okta, Google). **Permission sets** define the access and are assigned to users or groups in one or more accounts of an [organization](https://www.itwonderlab.com/aws-organizations/). Users sign in to a portal and receive temporary credentials, so there are no long-lived [IAM](https://www.itwonderlab.com/aws-iam/) users or access keys.

With Terraform: `aws_ssoadmin_permission_set`, `aws_ssoadmin_account_assignment` and the `aws_identitystore_*` data sources. See [multi-account setup](https://www.itwonderlab.com/terraform-aws-organizations-multi-account/).
