Supported Features
Account Creation Account DeletionPrerequisites
Step 1: Creating a Policy for Integration
-
Go to Identity and Access Management (IAM), and click [Create policy] from Policies in the left menu. For details, refer to Creating IAM policies (external site).

-
On the Create policy screen, click the JSON tab and overwrite with the following script.

-
Enter a name of your choice and click [Create policy] to save. (No other fields are required.)

Step 2: Creating a Role for Integration
-
Go to Identity and Access Management (IAM), and click Roles > Create role from the left menu.

-
On the Select trusted entity screen, enter the following values. When finished, click [Next].
- Trusted entity type: Select AWS account
- AWS account: Select Another AWS account and enter
162001151631as the account ID. - Check Require an external ID (Best practice when a third party will assume this role)
- For External ID, enter
a random alphanumeric string (no symbols, 24+ characters recommended). - Uncheck Require MFA.
- To add or remove users, grant these permissions to the role.

-
Select the policy created in Step 1, then click Next.

-
Set any role name and click [Create role]. (No other fields need to be edited.)

Setting Permissions to Create and Delete Customer-Managed Policies
To add or remove users, grant the following permissions to the role. For details, see the following resource. Controlling access to policies for creating, updating, and deleting customer-managed policies (external site).Step 3: Confirming the Role ARN
- Search for and open the role you created on the Roles screen.
-
The Role ARN will be displayed. Copy and save it.

Step 4: Confirming the Region and Workspace Key
Go to IAM Identity Center > Settings and copy and save theRegion and Identity store ID.

Integration Setup
- Go to Integrations > Integrations and search for AWS IAM Identity Center.
-
Enter the workspace key, region, Role ARN, and external ID obtained in the previous steps. These are the values set during role creation. Then click Connect.

- Once the AWS IAM Identity Center integration succeeds, registered user information will appear in the account list.

