Chapter 6: Introduction to AWS Organizations and AWS Single Sign-On
We've said several times that much of the confusion around applying identity to AWS stems from the various identity services available on the platform, and the ambiguity around their appropriate use. So far, we've split services into two groups: those that provide identity for AWS as an infrastructure-as-a-service platform, and those that offer identity capabilities in a platform-as-a-service (PaaS) context. AWS Single Sign-On (SSO) strains this motif. On the one hand, AWS SSO's primary function and capability focuses on facilitating access to AWS resources, specifically AWS accounts within an AWS organization. On the other, it is also capable of being an enterprise-grade identity provider for more than just AWS resources.
By the end of this chapter, we will understand AWS SSO's role in the AWS identity ecosystem, and how it operates as an identity service across AWS.
In this chapter, you...