AWS IAM Identity Center now allows you to disable AWS account access management during initial organization instance setup. This enables using the service solely for workforce identity integration with AWS applications, decoupling app SSO from account-level permissions. The change applies only to new instances and does not retroactively affect existing configurations.
- New org instances can now decouple app SSO from AWS account access management
- Use Identity Center for application access only, without managing account permissions
- Feature is available only at initial instance configuration stage
- Existing Identity Center instances remain unaffected by this change