IAM Identity Center is the AWS solution for connecting your workforce users to AWS managed application.
Identity Center Permission Sets are basically templates of IAM roles that will be provisioned in the account. When you assign a permission set to an account, the role is created and a trust policy to handle the federation is configured automatically.
It also supports SSO[Single Sign-On] as well as you could integrate 3rd party like AAD[Azure Active Directory] to this.
Getting Started:
First Go to that account Console with but for that you need to have IAM Role for that Or Root Account Holder.
Now, Edit the Instance name as it will be showed when you want to access through AWS Access Portal.
So, Link will be like that https://mizanzone.awsapps.com/start. And After login, we could see the Mizan tech Account For that specific account.
Permission & Others:
You need to create permissions sets. There are some predefined sets like below:
Here session is = aws access portal session after login.
Relay State: No need right now [it will forward to that URL what is set in the section]
You could set Custom Permission set there. Like only Ec2-admin/ S3-Access as You want per requirements.
Now we will create users and assign to the required groups. Please create users with mail-wise for the company. So that anyone could use their mail as Username.
When we have multiple accounts that time all the accounts will be listed above.
Now, we will use Access portal URL [https://mizanzone.awsapps.com/start/] and after login, we will get views like that
References:
SOCIAL SHARE CARD GENERATOR