---
title: AWS Identity Center
description: Configure the Advanced Identity Cloud AWS Identity Center application to manage users and groups between Advanced Identity Cloud and AWS IAM Identity Center
component: pingoneaic
page_id: pingoneaic:app-management:applications/aws-identity-center
canonical_url: https://docs.pingidentity.com/pingoneaic/app-management/applications/aws-identity-center.html
llms_txt: https://docs.pingidentity.com/pingoneaic/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
section_ids:
  register-the-application: Register the application
  aws-identity-center-requirements: AWS Identity Center requirements
  configure-the-provisioner: Configure the provisioner
  configure-provisioning-and-reconciliation-resources: Configure provisioning and reconciliation resources
---

# AWS Identity Center

AWS Identity Center helps you manage workforce identities and their access across AWS accounts and applications.

The Advanced Identity Cloud AWS Identity Center application lets you manage users, groups, and user group memberships between Advanced Identity Cloud and [AWS Identity Center](https://aws.amazon.com/iam/identity-center/). Learn more in [AWS IAM Identity Center connector](https://docs.pingidentity.com/openicf/connector-reference/aws-iam-identity-center.html).

|   |                                                                                              |
| - | -------------------------------------------------------------------------------------------- |
|   | To use this application, you must have an AWS administrator account for AWS Identity Center. |

## Register the application

1. In the Advanced Identity Cloud admin console, go to Applications > Applications, and click [icon: grid_view, set=material, size=inline] Browse App Catalog.

2. In the Browse App Catalog modal, select an application, and click Next.

3. Review the Application Integration information, and click Next.

4. In the Application Details window, specify the name, description, application owners, and logo for the application.

5. To make the application an [Authoritative](../register-an-application.html#target_and_authoritative_applications) source of identity data, select the Authoritative check box. This option is not available for every application.

6. Click Create Application.

## AWS Identity Center requirements

Before you can configure the Advanced Identity Cloud application, you need an AWS administrator account for AWS Identity Center. Sign on to the [AWS console](https://console.aws.amazon.com/) and make note of the following values:

* `accessKey`

* `secretKey`

* `roleArn`

* `roleSessionName`

* `region`

* `identityStoreId`

Use these values when you configure provisioning for an Advanced Identity Cloud AWS Identity Center application.

## Configure the provisioner

1. Complete [AWS Identity Center requirements](#aws-identity-center-requirements).

2. In the Advanced Identity Cloud admin console, on the Provisioning tab:

   * If setting up provisioning for the first time, click Set up Provisioning.

   * When editing existing settings in the Connection area, click Settings.

3. Configure the following fields:

   | Field             | Description                                                                               |
   | ----------------- | ----------------------------------------------------------------------------------------- |
   | Access Key        | The AWS access key ID used to access the AWS service API.                                 |
   | Secret Key        | The AWS secret access key associated with the access key ID.                              |
   | Role ARN          | The Amazon Resource Name (ARN) for the role.                                              |
   | Role Session Name | The name used to uniquely identify the role session.                                      |
   | Region            | The region where the AWS instance is hosted.                                              |
   | Identity Store ID | The unique identifier associated with the identity store used by AWS IAM Identity Center. |

4. Optionally, click Show advanced settings to set any of the following options:

   **Application specific settings**

   | Field                   | Description                                                                                                               |
   | ----------------------- | ------------------------------------------------------------------------------------------------------------------------- |
   | Session Expiration Time | The temporary credentials expiration time in seconds. Must be between 900 and 3600 seconds.                               |
   | Connection Timeout      | The timeout for the underlying HTTP connection in seconds.                                                                |
   | Max Connections         | The maximum size of the HTTP connection pool.                                                                             |
   | Read Rate Limit         | Defines throttling for read operations, either per second (`30/sec`) or per minute (`100/min`).                           |
   | Write Rate Limit        | Defines throttling for write operations (create, update, delete), either per second (`30/sec`) or per minute (`100/min`). |
   | Exclude Unmodified      | Select this option to synchronize only the modified properties on a target resource.                                      |

   **Pool configuration**

   | Field                                   | Description                                                                                                                                                                           |
   | --------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Max idle and active container instances | The maximum number of idle and active container instances. The default value is `10`.                                                                                                 |
   | Max Idle Connector Instances            | The maximum number of idle connector instances. The default value is `10`.                                                                                                            |
   | Set Timeout Period                      | Select to enable a timeout period for the connection. After enabling, configure the following:- Timeout period (ms): The timeout period in milliseconds.                              |
   | Set Minimum Idle Time                   | Select to set a minimum time (in milliseconds) before an idle object is removed. After enabling, configure the following:- Min idle time (ms): The minimum idle time in milliseconds. |
   | Min Idle Instances                      | The minimum number of idle connector instances.                                                                                                                                       |

   **Result Handler configuration**

   | Field                                                                   | Description                                                                       |
   | ----------------------------------------------------------------------- | --------------------------------------------------------------------------------- |
   | Enable for connectors with the attribute normalizer interface           | Enables the attribute normalizer interface for supported connectors.              |
   | Enable local filtering/search features                                  | Enables local filtering and search capabilities.                                  |
   | Enable case insensitive filter                                          | Configures filters to ignore case sensitivity.                                    |
   | Enable configuration of search attributes; disable for local connectors | Enables search attribute configuration. Disable this option for local connectors. |

   1. In the Operation Timeouts (ms) area, select the operations to enforce timeouts on and enter the duration in milliseconds.

      Available operations include Create, Validate, Test, Enable a Script on the Connector, Schema, Delete, Update, Sync, Authenticate, Get, Enable a Script on the Target, and Search.

   2. In the Operation Rate Limits area, select the operations to enforce rate limits on.

      You can enforce limits on specific operations, including Create, Validate, Test, Script on Connector, Schema, Delete, Update, Sync, Authenticate, Get, Script on Target, and Search.

      For each selected operation, configure the following fields:

      | Field           | Description                        |
      | --------------- | ---------------------------------- |
      | Request Limit   | Requests allowed over time.        |
      | Request Period  | Limit resets after this time (ms). |
      | Request Timeout | Time before exception thrown (ms). |

5. Click Connect.

6. Verify the information in the Details tab.

## Configure provisioning and reconciliation resources

Use the object type list to select a provisioning and reconciliation resource, such as `Account`. The selected object type determines the side tabs that display, as each resource has different provisioning and reconciliation requirements.

![Sub-tabs under the Provisioning tab](../_images/ui-workforce-provisioning.png)

| Provisioning side tab | Description                                                                                                                                                                                                                                                                                                | Related sections                                                                                                                                      |
| --------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------- |
| Details               | View and manage an application, including name, ID, and native type.                                                                                                                                                                                                                                       | Select the specific application from [Provision settings for an application](../provision-an-application.html#provision_settings_for_an_application). |
| Properties            | View and manage properties for the selected object type.                                                                                                                                                                                                                                                   | [Manage application attributes](../provision-an-application.html#manage_application_attributes)                                                       |
| Data                  | View data about the selected object type.                                                                                                                                                                                                                                                                  | [View user access data](../provision-an-application.html#view_user_access_data)                                                                       |
| Mapping               | View and manage mappings from the Advanced Identity Cloud admin console properties to external system properties and from external system properties to the Advanced Identity Cloud admin console properties.                                                                                              | [Manage mappings](../provision-an-application.html#manage_mappings)                                                                                   |
| Reconciliation        | Preview mappings on target applications between external systems and the Advanced Identity Cloud admin console, and reconcile the data between the two systems.View and manage rules for the users and groups that use your application.View and manage schedules for Full and Incremental reconciliation. | [Reconcile and synchronize end-user accounts](../provision-an-application.html#recon-sync-end-users)                                                  |
| Privacy & Consent     | Manage end-user data sharing and synchronization.                                                                                                                                                                                                                                                          | [Configure end-user data sharing](../provision-an-application.html#config-end-user-data-sharing)                                                      |
| Rules                 | View and manage provisioning rules for mappings between Advanced Identity Cloud and a target application.                                                                                                                                                                                                  | [Manage provisioning rules](../provision-an-application.html#manage-provisioning-rules)                                                               |
| Advanced Sync         | Create and manage mappings between a managed object type and an application or between applications.                                                                                                                                                                                                       | [Manage advanced sync](../provision-an-application.html#manage-advanced-sync)                                                                         |
