Gartner Research

Implementing an Identity Strategy for Amazon Web Services

Published: 24 February 2017

ID: G00292666

Analyst(s): Mark Diodati


The identity environment for AWS services is comprehensive, but complex. Technical professionals will appreciate features like OpenID Connect, Cognito User Pools, Active Directory services and AWS Organizations, but will face challenges in areas such as user and access management and access control.

Table Of Contents


  • Identity
    • AWS IAM User Directory
    • Amazon Cognito
    • Active Directory Services
    • Amazon Cloud Directory
  • Access Control
    • Policy Complexity
    • Managed Policies
    • AWS IAM Role
    • AWS Organizations
  • Authentication
    • Multifactor Authentication Options
    • Proprietary API Credentials
  • Federation
    • Proprietary
    • Security Assertion Markup Language
    • OpenID Connect
  • Administration
  • API
  • Identity Governance
    • Approaching the Governance Challenge
  • Strengths
  • Weaknesses


The Details

  • AWS User Types
    • AWS Account (aka Root Account)
    • AWS IAM
    • Proprietary Federation
    • Standards-Based Federation
    • Cognito and Cognito User Pool
    • AD Connector, Simple AD and AWS Microsoft AD
  • Authentication Methods
    • Passwords
    • Multifactor Authentication
    • SAML and OpenID Connect
    • Long-Term Credentials
    • Short-Term Credentials
  • Access Methods
    • Service Access vs. Resource Access
    • AWS Interfaces
    • AWS IAM User Access
    • Federation User Access — Proprietary Method
    • Federation User Access — Standards-Based Methods
    • Cognito User Access
  • Authorization Constructs
    • Policies
    • IAM Groups
    • IAM Roles
  • AWS's Active Directory Capabilities
    • AD Connector
    • Simple AD
    • AWS Microsoft AD
  • Auditing

Gartner Recommended Reading

©2021 Gartner, Inc. and/or its affiliates. All rights reserved. Gartner is a registered trademark of Gartner, Inc. and its affiliates. This publication may not be reproduced or distributed in any form without Gartner’s prior written permission. It consists of the opinions of Gartner’s research organization, which should not be construed as statements of fact. While the information contained in this publication has been obtained from sources believed to be reliable, Gartner disclaims all warranties as to the accuracy, completeness or adequacy of such information. Although Gartner research may address legal and financial issues, Gartner does not provide legal or investment advice and its research should not be construed or used as such. Your access and use of this publication are governed by Gartner’s Usage Policy. Gartner prides itself on its reputation for independence and objectivity. Its research is produced independently by its research organization without input or influence from any third party. For further information, see Guiding Principles on Independence and Objectivity.

Already have a Gartner Account?

Become a client

Learn how to access this content as a Gartner client.