Skip to main content

NOTICE: AWS Identity Center w/ Thoropass Access Review

A
Written by Annie Gregory
Updated over 2 months ago

NOTICE: AWS Identity Center w/ Thoropass Access Review

Context

This article applies only if you use AWS Identity Center (IC).

Why AWS Identity Center users aren’t included in Access Review

  • Thoropass does not support AWS Identity Center–managed user accounts in the Access Review workflow.

  • AWS does not provide an API that indicates whether an Identity Center account is enabled or disabled.

  • Because of this limitation, Thoropass Access Review includes only standard IAM accounts.

Recommended review approach when using an external Identity Provider (IdP)

Most organizations using AWS Identity Center authenticate through an external IdP (e.g., Okta, Azure AD, Google Workspace).

If your Identity Center users are managed through an IdP:

  1. Review user access directly in your IdP.

  2. Validate that no additional or manual configurations outside your IdP grant access to AWS through Identity Center.

  3. Use Thoropass Access Review to review IAM accounts only, ensuring full coverage when combined with your IdP review.

What Thoropass shows in Access Review

  • Thoropass surfaces a warning alert during Access Review when AWS Identity Center is detected, with a link to this article.


Summary

If you use AWS Identity Center with an external IdP, you must perform a separate IdP-based access review. Thoropass supports reviewing AWS IAM accounts only. Using both reviews together provides full visibility into AWS access.


Related articles

Did this answer your question?