Manage temporary elevated access in AWS IAM Identity Center
Provision and revoke temporary access to AWS accounts via IAM Identity Center (SSO). Assign permission sets to users or groups, look up users by email, and list accounts and permission sets for access request workflows.
List all AWS IAM Identity Center instances in your account
| パラメータ | 型 | 必須 | 説明 |
|---|
region | string | はい | AWS region (e.g., us-east-1) |
accessKeyId | string | はい | AWS access key ID |
secretAccessKey | string | はい | AWS secret access key |
maxResults | number | いいえ | Maximum number of instances to return (1-100) |
nextToken | string | いいえ | Pagination token from a previous request |
| パラメータ | 型 | 説明 |
|---|
instances | json | List of Identity Center instances with instanceArn, identityStoreId, name, status, statusReason |
nextToken | string | Pagination token for the next page of results |
count | number | Number of instances returned |
List all AWS accounts in your organization
| パラメータ | 型 | 必須 | 説明 |
|---|
region | string | はい | AWS region (e.g., us-east-1) |
accessKeyId | string | はい | AWS access key ID |
secretAccessKey | string | はい | AWS secret access key |
maxResults | number | いいえ | Maximum number of accounts to return |
nextToken | string | いいえ | Pagination token from a previous request |
| パラメータ | 型 | 説明 |
|---|
accounts | json | List of AWS accounts with id, arn, name, email, status |
nextToken | string | Pagination token for the next page of results |
count | number | Number of accounts returned |
Retrieve details about a specific AWS account by its ID
| パラメータ | 型 | 必須 | 説明 |
|---|
region | string | はい | AWS region (e.g., us-east-1) |
accessKeyId | string | はい | AWS access key ID |
secretAccessKey | string | はい | AWS secret access key |
accountId | string | はい | AWS account ID to describe |
| パラメータ | 型 | 説明 |
|---|
id | string | AWS account ID |
arn | string | AWS account ARN |
name | string | Account name |
email | string | Root email address of the account |
status | string | Account status (ACTIVE, SUSPENDED, etc.) |
joinedTimestamp | string | Date the account joined the organization |
List all permission sets defined in an IAM Identity Center instance
| パラメータ | 型 | 必須 | 説明 |
|---|
region | string | はい | AWS region (e.g., us-east-1) |
accessKeyId | string | はい | AWS access key ID |
secretAccessKey | string | はい | AWS secret access key |
instanceArn | string | はい | ARN of the Identity Center instance |
maxResults | number | いいえ | Maximum number of permission sets to return |
nextToken | string | いいえ | Pagination token from a previous request |
| パラメータ | 型 | 説明 |
|---|
permissionSets | json | List of permission sets with permissionSetArn, name, description, sessionDuration |
nextToken | string | Pagination token for the next page of results |
count | number | Number of permission sets returned |
Look up a user in the Identity Store by email address
| パラメータ | 型 | 必須 | 説明 |
|---|
region | string | はい | AWS region (e.g., us-east-1) |
accessKeyId | string | はい | AWS access key ID |
secretAccessKey | string | はい | AWS secret access key |
identityStoreId | string | はい | Identity Store ID (from the Identity Center instance) |
email | string | はい | Email address of the user to look up |
| パラメータ | 型 | 説明 |
|---|
userId | string | Identity Store user ID (use as principalId) |
userName | string | Username in the Identity Store |
displayName | string | Display name of the user |
email | string | Email address of the user |
Look up a group in the Identity Store by display name
| パラメータ | 型 | 必須 | 説明 |
|---|
region | string | はい | AWS region (e.g., us-east-1) |
accessKeyId | string | はい | AWS access key ID |
secretAccessKey | string | はい | AWS secret access key |
identityStoreId | string | はい | Identity Store ID (from the Identity Center instance) |
displayName | string | はい | Display name of the group to look up |
| パラメータ | 型 | 説明 |
|---|
groupId | string | Identity Store group ID (use as principalId) |
displayName | string | Display name of the group |
description | string | Group description |
List all groups in the Identity Store
| パラメータ | 型 | 必須 | 説明 |
|---|
region | string | はい | AWS region (e.g., us-east-1) |
accessKeyId | string | はい | AWS access key ID |
secretAccessKey | string | はい | AWS secret access key |
identityStoreId | string | はい | Identity Store ID (from the Identity Center instance) |
maxResults | number | いいえ | Maximum number of groups to return |
nextToken | string | いいえ | Pagination token from a previous request |
| パラメータ | 型 | 説明 |
|---|
groups | json | List of groups with groupId, displayName, description |
nextToken | string | Pagination token for the next page of results |
count | number | Number of groups returned |
Grant a user or group access to an AWS account via a permission set (temporary elevated access)
| パラメータ | 型 | 必須 | 説明 |
|---|
region | string | はい | AWS region (e.g., us-east-1) |
accessKeyId | string | はい | AWS access key ID |
secretAccessKey | string | はい | AWS secret access key |
instanceArn | string | はい | ARN of the Identity Center instance |
accountId | string | はい | AWS account ID to grant access to |
permissionSetArn | string | はい | ARN of the permission set to assign |
principalType | string | はい | Type of principal: USER or GROUP |
principalId | string | はい | Identity Store ID of the user or group |
| パラメータ | 型 | 説明 |
|---|
message | string | Status message |
status | string | Provisioning status: IN_PROGRESS, FAILED, or SUCCEEDED |
requestId | string | Request ID to use with Check Assignment Status |
accountId | string | Target AWS account ID |
permissionSetArn | string | Permission set ARN |
principalType | string | Principal type (USER or GROUP) |
principalId | string | Principal ID |
failureReason | string | Reason for failure if status is FAILED |
createdDate | string | Date the request was created |
Revoke a user or group access to an AWS account by removing a permission set assignment
| パラメータ | 型 | 必須 | 説明 |
|---|
region | string | はい | AWS region (e.g., us-east-1) |
accessKeyId | string | はい | AWS access key ID |
secretAccessKey | string | はい | AWS secret access key |
instanceArn | string | はい | ARN of the Identity Center instance |
accountId | string | はい | AWS account ID to revoke access from |
permissionSetArn | string | はい | ARN of the permission set to remove |
principalType | string | はい | Type of principal: USER or GROUP |
principalId | string | はい | Identity Store ID of the user or group |
| パラメータ | 型 | 説明 |
|---|
message | string | Status message |
status | string | Deprovisioning status: IN_PROGRESS, FAILED, or SUCCEEDED |
requestId | string | Request ID to use with Check Assignment Status |
accountId | string | Target AWS account ID |
permissionSetArn | string | Permission set ARN |
principalType | string | Principal type (USER or GROUP) |
principalId | string | Principal ID |
failureReason | string | Reason for failure if status is FAILED |
createdDate | string | Date the request was created |
Check the provisioning status of an account assignment creation request
| パラメータ | 型 | 必須 | 説明 |
|---|
region | string | はい | AWS region (e.g., us-east-1) |
accessKeyId | string | はい | AWS access key ID |
secretAccessKey | string | はい | AWS secret access key |
instanceArn | string | はい | ARN of the Identity Center instance |
requestId | string | はい | Request ID returned from Create or Delete Account Assignment |
| パラメータ | 型 | 説明 |
|---|
message | string | Human-readable status message |
status | string | Current status: IN_PROGRESS, FAILED, or SUCCEEDED |
requestId | string | The request ID that was checked |
accountId | string | Target AWS account ID |
permissionSetArn | string | Permission set ARN |
principalType | string | Principal type (USER or GROUP) |
principalId | string | Principal ID |
failureReason | string | Reason for failure if status is FAILED |
createdDate | string | Date the request was created |
Check the deprovisioning status of an account assignment deletion request
| パラメータ | 型 | 必須 | 説明 |
|---|
region | string | はい | AWS region (e.g., us-east-1) |
accessKeyId | string | はい | AWS access key ID |
secretAccessKey | string | はい | AWS secret access key |
instanceArn | string | はい | ARN of the Identity Center instance |
requestId | string | はい | Request ID returned from Delete Account Assignment |
| パラメータ | 型 | 説明 |
|---|
message | string | Human-readable status message |
status | string | Current deletion status: IN_PROGRESS, FAILED, or SUCCEEDED |
requestId | string | The deletion request ID that was checked |
accountId | string | Target AWS account ID |
permissionSetArn | string | Permission set ARN |
principalType | string | Principal type (USER or GROUP) |
principalId | string | Principal ID |
failureReason | string | Reason for failure if status is FAILED |
createdDate | string | Date the request was created |
List all account assignments for a specific user or group across all accounts
| パラメータ | 型 | 必須 | 説明 |
|---|
region | string | はい | AWS region (e.g., us-east-1) |
accessKeyId | string | はい | AWS access key ID |
secretAccessKey | string | はい | AWS secret access key |
instanceArn | string | はい | ARN of the Identity Center instance |
principalId | string | はい | Identity Store ID of the user or group |
principalType | string | はい | Type of principal: USER or GROUP |
maxResults | number | いいえ | Maximum number of assignments to return |
nextToken | string | いいえ | Pagination token from a previous request |
| パラメータ | 型 | 説明 |
|---|
assignments | json | List of account assignments with accountId, permissionSetArn, principalType, principalId |
nextToken | string | Pagination token for the next page of results |
count | number | Number of assignments returned |