Using IAM Identity Center across multiple AWS Regions - AWS IAM Identity Center

Using IAM Identity Center across multiple AWS Regions

This topic explains how to use AWS IAM Identity Center across multiple AWS Regions. Learn how to replicate your instance to additional Regions, manage workforce access and sessions, deploy applications, and maintain account access during service disruptions.

When you enable an organization instance of IAM Identity Center, you choose a single AWS Region (primary Region). You can replicate this instance to additional AWS Regions if it meets certain prerequisites. IAM Identity Center automatically replicates workforce identities, permission sets, user and group assignments, sessions, and other metadata from the primary Region to the chosen additional Regions.

Benefits of multi-Region support

Replicating IAM Identity Center to additional AWS Regions provides two key benefits:

  • Improved resiliency of AWS account access – Your workforce can access their AWS accounts even if the IAM Identity Center instance experiences a service disruption in its primary Region. This applies to access with permissions provisioned before the disruption.

  • Enhanced flexibility in choosing deployment Regions for AWS managed applications – You can deploy AWS managed applications in your preferred Regions to meet application data residency requirements and improve performance through proximity to users. Applications deployed in additional Regions access replicated workforce identities locally for optimal performance and reliability.

Prerequisites and considerations

Before you replicate your IAM Identity Center instance, ensure the following requirements are met:

Choosing an additional Region

When choosing an additional Region among commercial Regions enabled by default, consider these factors:

  • Compliance requirements – If you need to run AWS managed applications that access datasets limited to a specific Region for compliance reasons, choose the Region where the datasets reside.

  • Performance optimization – If data residency isn't a factor, select a Region closest to your application users to optimize their experience.

  • Application support – Verify that your required AWS applications are available in your chosen Region.

  • AWS account access resiliency – For continuity of access to AWS accounts, choose a Region geographically distant from the primary Region of your IAM Identity Center instance.

Note

IAM Identity Center has a quota on the number of AWS Regions. For more information, see Additional quotas.