The Identity Store holds Identity Center's users and groups. Because permission-set assignments target users and groups, write access to the store lets you add yourself to a group that already carries assignments, or create a user mapped to privileged access.
Join a privileged group#
aws identitystore list-groups --identity-store-id <store-id>
aws identitystore create-group-membership --identity-store-id <store-id> \
--group-id <privileged-group-id> \
--member-id UserId=<your-user-id>
Exploitation notes#
- Target groups that already hold account assignments: membership inherits those permission sets without touching the assignments themselves.
- When Identity Center syncs from an external IdP (SCIM), the external directory is the real control point; changes may be overwritten on the next sync, so this is strongest on an internally-managed store.
- Pair with permission set: the store decides who, the permission set decides what.
Tools#
- AWS CLI (
identitystorecommands).