Why does Amazon Managed Grafana require the organization-wide IAM Identity Center instance?

0
0
Asked By MapleRidge42 On

Amazon Managed Grafana currently integrates only with the organization instance of IAM Identity Center; account-level Identity Center instances aren't supported. In a large AWS organization, each member account may belong to a separate team or client with its own access boundaries, so using one centralized identity directory isn't ideal. Is there a technical or architectural reason account instances aren't supported? Without that option, teams may need to run an external identity provider such as Keycloak.

1 Answer

Answered By QuietHarbor7 On

There doesn’t appear to be a documented explanation beyond this being a product limitation. The organization instance is designed for centralized identity and access management across accounts, and Managed Grafana may depend on that integration model. Unfortunately, knowing the rationale wouldn’t provide a workaround—your practical choices are to use the organization-wide instance or integrate Grafana with another supported identity provider, such as a self-hosted solution.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.