Skip to main content

NOTICE: AWS Identity Center w/ Thoropass Access Review

A
Written by Annie Gregory
Updated this week

NOTICE: AWS Identity Center w/ Thoropass Access Review

Context

This article applies only if you use AWS Identity Center (IC).

Why AWS Identity Center users aren’t included in Access Review

  • Thoropass does not support AWS Identity Center–managed user accounts in the Access Review workflow.

  • AWS does not provide an API that indicates whether an Identity Center account is enabled or disabled.

  • Because of this limitation, no single integration can fully obtain BOTH the Identity Center accounts and IAM accounts at the same time. AWS integration now focuses on what is 100% accurate: IAM accounts.

Recommended: Do separate access reviews for IAM users and Identity Provider (IdP) managed users (through Identity Center)

Identity providers do not capture critical review objects such as service accounts. The only way to have a thorough review of AWS if you use Identity Center is to do both a review of your IdP access and IAM access.

The Thoropass integration to AWS can accurately review your IAM users, and your IdP review can handle

If your Identity Center users are managed through an IdP:

  • Review user access directly in your IdP.

  • Validate that no additional or manual configurations outside your IdP grant access to AWS through Identity Center.

  • Use Thoropass Access Review to review IAM accounts only, ensuring full coverage when combined with your IdP review.

To do separate reviews of AWS IC and AWS (IAM) in Thoropass, treat the integrated AWS as the "IAM" half. Then, create a new system for Identity Center:

  1. From Vendors, Add the AWS Identity Center (For Access Review) vendor and complete the workflow.

  2. From your access review, use the "Add System" button to add the Identity Center system.

  3. Perform separate access reviews, using your IdP screenshots or exports for Identity Center and the Thoropass integration to AWS for IAM users.

What Thoropass shows in Access Review

  • Thoropass surfaces a warning alert during Access Review when AWS Identity Center is detected, with a link to this article.


Summary

If you use AWS Identity Center with an external IdP, you must perform a separate IdP-based access review. Thoropass supports reviewing AWS IAM accounts through the AWS integration. Using both reviews together provides full visibility into AWS access.


Related articles

Did this answer your question?