Add users and groups to your sync scope
Note
When adding groups to your sync scope, sync groups directly from the trusted on-premises domain rather than from groups in the AWS Managed Microsoft AD domain. Groups synced directly from the trusted domain contain actual user objects that IAM Identity Center can access and synchronize successfully.
Add your Active Directory users and groups to IAM Identity Center by following these steps.
To add users
-
Open the IAM Identity Center console.
-
Choose Settings.
-
On the Settings page, choose the Identity source tab, choose Actions, and then choose Manage Sync.
-
On the Manage Sync page, choose the Users tab, and then choose Add users and groups.
-
On the Users tab, under User, enter the exact user name and choose Add.
-
Under Added Users and Groups, review the user that you want to add.
-
Choose Submit.
-
In the navigation pane, choose Users. If the user that you specified doesn't display in the list, choose the refresh icon to update the list of users.
To add groups
-
Open the IAM Identity Center console.
-
Choose Settings.
-
On the Settings page, choose the Identity source tab, choose Actions, and then choose Manage Sync.
-
On the Manage Sync page, choose the Groups tab, and then choose Add users and groups.
-
Choose the Groups tab. Under Group, enter the exact group name and choose Add.
-
Under Added Users and Groups, review the group that you want to add.
-
Choose Submit.
-
In the navigation pane, choose Groups. If the group that you specified doesn't display in the list, choose the refresh icon to update the list of groups.