LowerPlane

AWS Identity Store Integration

Automate identity and access management evidence for AWS SSO. Track user provisioning, permission sets, group memberships, and authentication logs for SOC 2, ISO 27001, HIPAA, and FedRAMP compliance.

Supported Frameworks:SOC 2ISO 27001HIPAAFedRAMP

What Gets Automated

Continuous AWS SSO directory and access evidence collection with zero manual exports

User Management

  • User provisioning records
  • User deprovisioning events
  • Group memberships tracking
  • User attribute management
  • Identity source configuration
  • User status monitoring

Access Control

  • Permission set assignments
  • Account access assignments
  • MFA configuration status
  • Session policy enforcement
  • Role-based access control
  • Cross-account access tracking

Audit & Compliance

  • User login events
  • Permission set changes
  • Group modification logs
  • Policy update tracking
  • Failed authentication attempts
  • Administrative actions audit

Setup in 3 Minutes

Simple IAM role configuration with read-only permissions

1
1 min

Configure IAM Role

In AWS Console, create a read-only IAM role with Identity Store permissions. Attach the managed policy "AWSSSOMasterAccountAdministrator" with read-only custom policy restrictions, or use our provided CloudFormation template for automated setup.

2
1 min

Enable CloudTrail

Ensure CloudTrail is enabled in your AWS Organization management account with Identity Store event logging. Configure S3 bucket access for LowerPlane to read Identity Store API events, user authentication logs, and permission changes.

3
1 min

Connect & Sync

In LowerPlane, enter your AWS account ID, IAM role ARN, and Identity Store ID. Click "Test Connection" to verify access, then enable automated evidence collection. Initial sync completes within 5 minutes for typical directories.

Security Note

LowerPlane requires read-only IAM permissions and cannot modify your AWS Identity Store configuration, users, or permission sets. All credentials are encrypted at rest using AES-256 and access is logged for audit purposes. The IAM role uses external ID for secure cross-account access and can be revoked at any time.

Evidence Collected Automatically

Real-time AWS SSO directory and access evidence mapped directly to compliance controls

ControlEvidence TypeServiceFrequency
User DirectorySOC 2
Complete user list with statusIdentity Store APIDaily
MFA EnforcementISO 27001
MFA device configurationIdentity Store APIDaily
Permission Set AssignmentsFedRAMP
Account access mappingsSSO Admin APIDaily
Group MembershipsSOC 2
User-to-group assignmentsIdentity Store APIDaily
Access LogsHIPAA
Authentication eventsCloudTrailContinuous
Policy ChangesISO 27001
Permission set modificationsCloudTrailContinuous

Supporting AWS SSO user directory, authentication, and multi-account access management

View complete evidence documentation

Framework Coverage

AWS Identity Store integration satisfies identity and access controls across multiple compliance frameworks

10

SOC 2 Type II Controls

AWS Identity Store integration covers 10 critical SOC 2 controls focused on centralized identity management, SSO authentication, and multi-account access governance.

Common Criteria (CC)

  • CC6.1 - Logical Access Controls
  • CC6.2 - Authentication Management
  • CC6.3 - Authorization Management
  • CC6.6 - Logical Access Removal

Additional Criteria

  • CC7.2 - System Monitoring
  • CC8.1 - Change Management
  • A1.2 - Confidential Data Access
  • P2.1 - Privacy Access Controls

Trusted by AWS-First Organizations

35% of our customers use AWS Identity Store for centralized identity management

35%
Of customers use AWS Identity Store
3K+
User identities monitored
100K
Authentication events tracked monthly
30min
Average time saved per access review

"AWS Identity Store integration eliminated manual SSO access reviews entirely. Instead of manually exporting permission sets and cross-referencing account assignments across 12 AWS accounts, LowerPlane tracks everything automatically. Our FedRAMP auditors were impressed by the real-time visibility."

DK
David Kim
Director of Cloud Security, CloudCorp
FedRAMP + SOC 2 Type II Certified
AWS Identity Store Partner
SOC 2
SOC 2
ISO 27001
ISO 27001
HIPAA
HIPAA
FedRAMP
FedRAMP

Frequently Asked Questions

Everything you need to know about AWS Identity Store integration

Still have questions?

Contact our security team

Related Integrations

Build comprehensive identity and access security coverage across cloud providers

Ready to automate AWS Identity Store compliance?

Connect your AWS SSO directory in 3 minutes and start tracking identity evidence automatically

No credit card required • 14-day free trial • Setup in 3 minutes