tag: Identity · 3 items
- Platform/SRE — Plan: If your org uses HCP (Vault, Terraform Cloud, etc.) and an external IdP, evaluate enabling SCIM provisioning to automate user/group sync and reduce manual access management overhead; no deadline, but worth scheduling this quarter.
- CI/CD — Skip
- Leader — Plan: SCIM provisioning on HCP reduces IAM admin overhead and improves access consistency across HCP services — worth adding to your identity governance standards review if the org is standardized on HashiCorp HCP.
- Platform/SRE — Learn: New configuration option for net-new IAM Identity Center instances reduces the service-linked role footprint when only AWS application SSO is needed. Worth noting for future greenfield deployments; no action required on existing instances.
- CI/CD — Skip
- Leader — Learn: Reduces the access surface when standardizing on IAM Identity Center for application SSO without requiring full AWS account management delegation — useful context when evaluating identity architecture for new AWS org setups.
- Platform/SRE — Learn: IAM Identity Center can now be used for FedRAMP Class C workloads in four US regions — relevant if you operate in a federal or regulated environment, but no action required for non-FedRAMP shops.
- CI/CD — Skip
- Leader — Learn: Broadens the compliance posture of a core AWS identity service; worth noting for organizations pursuing or maintaining FedRAMP authorization, but no strategic decision is forced without an active compliance program in scope.