IAM and IAM Access Analyzer in AWS European Sovereign Cloud
This topic describes the functionality of IAM and IAM Access Analyzer in the AWS European Sovereign Cloud Region.
AWS Identity and Access Management (IAM) is a web service for securely controlling access to AWS services. With IAM, you can centrally manage users, security credentials such as access keys, and permissions that control which AWS resources users and applications can access.
How AWS Identity and Access Management differs
The following differences apply to IAM and IAM Access Analyzer:
-
There is no AWS STS global endpoint in the AWS European Sovereign Cloud Region. AWS provides Regional AWS STS endpoints.
-
Only some AWS services support service-linked roles in the AWS European Sovereign Cloud Region. For information about which services support using service-linked roles, see AWS Services That Work with IAM and look for the services that have Yes in the Service-Linked Role column. To learn whether the service supports service-linked roles in a specific region, choose the Yes link to view the service-linked role documentation for that service.
-
Amazon Resource Names (ARNs) and endpoints have different values.
-
Service Quotas integration for IAM is not available.
-
Independent Service Vendor Delegated Access support is not available.
-
JWT assertions are not available.
-
PrivateLink for AWS Sign-In is not available.
-
Console credentials for local development (
aws logincommand) are not available.
Documentation
-
IAM and IAM Access Analyzer documentation
-
AWS Developer Tools in AWS European Sovereign Cloud
-
Service endpoints for AWS European Sovereign Cloud