AWS IAM Identity Center (formerly AWS SSO) is the front door to an entire organization: it maps workforce users to permission sets in member accounts. Control over its assignments or its user directory turns one foothold into access across every account it manages.
Pages#
- Permission set: assigning or editing a permission set to grant yourself a role in a target account.
- Identity Store: adding or modifying users and group membership to inherit their access.