Introduction to Identity Center

Last Updated At: 2025-10-21 09:10:00

Identity Center provides unified identity and permission management for multiple accounts based on the structure of the cloud organization. Using the Identity Center feature of Cloud Organization, you can centrally manage cloud platform users in your enterprise, configure the enterprise identity management system with the cloud platform's single sign-on (SSO) in one go, and centrally configure user access permissions on multiple accounts.

Features

  • Unified management of cloud platform users
    Identity Center offers you a user management module where you can maintain all users who need to access the cloud platform. You can manage users and user groups manually or use the System for Cross-domain Identity Management (SCIM) protocol to synchronize users and user groups from your enterprise identity management system to Identity Center.
  • Unified configuration of SSO with your enterprise identity management system
    Identity Center supports enterprise-level SSO based on the Security Assertion Markup Language (SAML) 2.0 protocol. Only a one-time configuration in both Identity Center and the enterprise identity management system is needed to set up SSO.
  • Unified configuration of user access permissions on multiple accounts
    By leveraging the structure of your cloud organization, you can centrally configure user or user group permissions to access any member account within the enterprise in Identity Center. These permissions can be modified or deleted at any time.
  • Unified login portal
    Identity Center provides a unified login portal where enterprise employees can access all accounts they are authorized to use with a single login. They can then log in to the cloud platform console and easily switch between multiple accounts.

Relationship Between Identity Center and CAM

  • CAM provides identity and permission management within a single cloud platform account. CAM offers user management (including users, user groups, and roles), SSO, and permission configuration, but these are only effective within one cloud platform account. When your enterprise has multiple cloud platform accounts, you need to use CAM in each account to manage users separately and to configure SSO and permissions separately, which poses significant management challenges.
  • Identity Center provides unified identity and permission management across multiple accounts within an organization. With Identity Center, you can perform unified configuration once, achieving user management and SSO for multiple cloud platform accounts. To achieve this, Identity Center offers identity management independent of CAM, but its permission configuration reuses the permission policies in CAM. Additionally, the access of Identity Center users to accounts is essentially another SSO performed by Identity Center users assuming the CAM role in each account.
  • When you start using Identity Center for unified identity and permission management of your cloud organization, you will no longer need to use CAM to manage individual accounts. However, in certain cases, for example, when you have existing CAM users and CAM roles, or when you need to use access keys for programmatic access to cloud platform resources, you can still use CAM within individual accounts. Using Identity Center does not restrict the original features of CAM. Both services can be used simultaneously.