Why does Amazon Managed Grafana require an organization-wide IAM Identity Center instance?

0
0
Asked By MellowPine42 On

Amazon Managed Grafana currently integrates only with the organization instance of IAM Identity Center; account-level Identity Center instances aren't supported. In a large organization, each member account may belong to a separate team or client with its own access boundaries, so using a shared organization-wide identity directory isn't ideal. Is there a known reason for this limitation, or any planned support for member-account Identity Center instances? If not, are there recommended alternatives besides self-hosting an identity provider such as Keycloak?

1 Answer

Answered By QuietHarbor7 On

AWS hasn’t provided a detailed public explanation for this limitation. The integration appears to be designed around centralized, organization-level IAM Identity Center administration, so account instances don’t fit the current AMG authentication model. For now, the practical choices are to use the organization instance with carefully separated groups and permission sets, or put an external identity provider in front of Grafana. If strict account-level isolation is required, self-hosting an identity solution may be one of the few viable alternatives.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.