Select your cookie preferences

We use essential cookies and similar tools that are necessary to provide our site and services. We use performance cookies to collect anonymous statistics, so we can understand how customers use our site and make improvements. Essential cookies cannot be deactivated, but you can choose “Customize” or “Decline” to decline performance cookies.

If you agree, AWS and approved third parties will also use cookies to provide useful site features, remember your preferences, and display relevant content, including relevant advertising. To accept or decline all non-essential cookies, choose “Accept” or “Decline.” To make more detailed choices, choose “Customize.”

Manage Permissions for Entities with IAM

Focus mode
Manage Permissions for Entities with IAM - AWS Control Tower

AWS Identity and Access Management (IAM) is an AWS service for controlling access to other AWS services. With IAM, you can centrally manage users, security credentials—such as access keys, and permissions—that designate the AWS resources to which your users and applications are granted access.

When you set up your landing zone, a number of groups can be created for AWS IAM Identity Center automatically, if you select IAM as your identity provider. These groups have permission sets that are pre-defined permissions policies from IAM. Your end-users also can use IAM to define the scope of permissions for IAM users and other entities within member accounts.

AWS Identity and Access Management (IAM) simplifies how you manage access to AWS accounts and business applications. You can control IAM Identity Center access and user permissions across all your AWS accounts in AWS Control Tower.

For more information, see AWS IAM Identity Center User Guide.

If you are based in an AWS Region that does not support IAM, you can bring another identity provider, to set up and maintain your own users and groups manually.

PrivacySite termsCookie preferences
© 2025, Amazon Web Services, Inc. or its affiliates. All rights reserved.