Amazon Managed Grafana currently integrates only with the organization instance of IAM Identity Center; account-level Identity Center instances aren't supported. In a large organization, each member account may belong to a separate team or client with its own access boundaries, so using a shared organization-wide identity directory isn't ideal. Is there a known reason for this limitation, or any planned support for member-account Identity Center instances? If not, are there recommended alternatives besides self-hosting an identity provider such as Keycloak?
1 Answer
AWS hasn’t provided a detailed public explanation for this limitation. The integration appears to be designed around centralized, organization-level IAM Identity Center administration, so account instances don’t fit the current AMG authentication model. For now, the practical choices are to use the organization instance with carefully separated groups and permission sets, or put an external identity provider in front of Grafana. If strict account-level isolation is required, self-hosting an identity solution may be one of the few viable alternatives.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures