Description
Direct user creation is a supported way to manage AWS IAM Identity Center. Where an external IdP or central directory is the identity source, manual or Terraform management must stay aligned with synchronization and offboarding procedures.
Assign responsibility for disabling accounts, organizational changes and access removal. Creating a user alone does not grant AWS account access; permission sets and assignments require separate management.
Potential impact
- Distributed user administration can delay account and access removal when people leave or change roles.
- Users omitted from central lifecycle processes may retain unnecessary access.
Remediation
- Align creation, updates and deletion with the selected Identity Center identity source. Configure supported provisioning integration when using an external IdP.
- Establish approval and lifecycle ownership for directly managed users, and regularly review users, groups and account assignments.
Examples
Provide the actual Identity Center instance and identity source. Switching to a data source does not configure external IdP synchronization by itself.
Before
hcl
resource "aws_identitystore_user" "example" {
identity_store_id = tolist(data.aws_ssoadmin_instances.example.identity_store_ids)[0]
display_name = "John Doe"
user_name = "johndoe"
name {
given_name = "John"
family_name = "Doe"
}
emails {
value = "john@example.com"
}
}
After
hcl
data "aws_ssoadmin_instances" "example" {}
# This user is provisioned in advance through SCIM by an external IdP.
# Terraform retrieves the existing user rather than creating one.
data "aws_identitystore_user" "example" {
identity_store_id = tolist(data.aws_ssoadmin_instances.example.identity_store_ids)[0]
alternate_identifier {
unique_attribute {
attribute_path = "UserName"
attribute_value = "john.doe@example.com"
}
}
}
Explanation:
- Before: Terraform manages the user. Verify that this matches the organization’s chosen identity-management model.
- After: Retrieves an already provisioned user. Plan the transition so removing a managed resource does not inadvertently delete the actual user.