AWS Security Blog
Use IAM Identity Center APIs to audit and manage application assignments
You can now use AWS IAM Identity Center application assignment APIs to programmatically manage and audit user and group access to AWS managed applications. Previously, you had to use the IAM Identity Center console to manually assign users and groups to an application. Now, you can automate this task so that you scale more effectively as […]
How to use multiple instances of AWS IAM Identity Center
February 29, 2024: This post has been updated to include the account instances opt-in feature supported for member accounts in AWS Organizations. November 28, 2023: This blog has been updated to include Identity Center instances deployment patterns. November 22, 2023: We updated the information about account instances of Identity Center availability. Recently, AWS launched a […]
Establishing a data perimeter on AWS: Allow access to company data only from expected networks
November 24, 2025: We updated this post to include newly launched condition keys. August 28, 2025: This post has been updated with guidance on how to use aws:VpceOrgID condition key to scale your network perimeter implementation. November 13, 2024: This post has been updated with guidance on how to use resource control policies (RCPs) to […]
Establishing a data perimeter on AWS: Allow only trusted resources from my organization
September 19, 2025: This post was updated to reflect that AWS Organizations now offers full IAM policy language support for service control policies (SCPs). Details of this new feature are outlined in this post. Companies that store and process data using Amazon Web Services (AWS) want to prevent transfers of that data to or from locations outside […]



