AWS Single Sign-On Admin

2026/09/22 - AWS Single Sign-On Admin - 2 updated api methods

Changes  AWS IAM Identity Center now returns PrimaryRegion and Regions in the DescribeInstance response, providing information about replicated instances, and returns IdentityStoreArn in both the ListInstances and DescribeInstance responses.

DescribeInstance (updated) Link ¶
Changes (response)
{'IdentityStoreArn': 'string',
 'PrimaryRegion': 'string',
 'Regions': [{'AddedDate': 'timestamp',
              'IsPrimaryRegion': 'boolean',
              'RegionName': 'string',
              'Status': 'ACTIVE | ADDING | REMOVING'}]}

Returns the details of an instance of IAM Identity Center. The status can be one of the following:

  • CREATE_IN_PROGRESS - The instance is in the process of being created. When the instance is ready for use, DescribeInstance returns the status of ACTIVE. While the instance is in the CREATE_IN_PROGRESS state, you can call only DescribeInstance and DeleteInstance operations.

  • DELETE_IN_PROGRESS - The instance is being deleted. Returns AccessDeniedException after the delete operation completes.

  • ACTIVE - The instance is active.

See also: AWS API Documentation

Request Syntax

client.describe_instance(
    InstanceArn='string'
)
type InstanceArn:

string

param InstanceArn:

[REQUIRED]

The ARN of the instance of IAM Identity Center under which the operation will run.

rtype:

dict

returns:

Response Syntax

{
    'InstanceArn': 'string',
    'IdentityStoreId': 'string',
    'IdentityStoreArn': 'string',
    'OwnerAccountId': 'string',
    'Name': 'string',
    'CreatedDate': datetime(2015, 1, 1),
    'Status': 'CREATE_IN_PROGRESS'|'CREATE_FAILED'|'DELETE_IN_PROGRESS'|'ACTIVE',
    'StatusReason': 'string',
    'PrimaryRegion': 'string',
    'Regions': [
        {
            'RegionName': 'string',
            'Status': 'ACTIVE'|'ADDING'|'REMOVING',
            'AddedDate': datetime(2015, 1, 1),
            'IsPrimaryRegion': True|False
        },
    ],
    'EncryptionConfigurationDetails': {
        'KeyType': 'AWS_OWNED_KMS_KEY'|'CUSTOMER_MANAGED_KEY',
        'KmsKeyArn': 'string',
        'EncryptionStatus': 'UPDATING'|'ENABLED'|'UPDATE_FAILED',
        'EncryptionStatusReason': 'string'
    },
    'PermissionSetsEnabled': True|False
}

Response Structure

  • (dict) --

    • InstanceArn (string) --

      The ARN of the instance of IAM Identity Center under which the operation will run. For more information about ARNs, see Amazon Resource Names (ARNs) and Amazon Web Services Service Namespaces in the Amazon Web Services General Reference.

    • IdentityStoreId (string) --

      The identifier of the identity store that is connected to the instance of IAM Identity Center.

    • IdentityStoreArn (string) --

      The ARN of the identity store that is connected to the instance of IAM Identity Center.

    • OwnerAccountId (string) --

      The identifier of the Amazon Web Services account for which the instance was created.

    • Name (string) --

      Specifies the instance name.

    • CreatedDate (datetime) --

      The date the instance was created.

    • Status (string) --

      The status of the instance.

    • StatusReason (string) --

      Provides additional context about the current status of the IAM Identity Center instance. This field is particularly useful when an instance is in a non-ACTIVE state, such as CREATE_FAILED. When an instance fails to create or update, this field contains information about the cause, which may include issues with KMS key configuration, permission problems with the specified KMS key, or service-related errors.

    • PrimaryRegion (string) --

      The primary Region where the IAM Identity Center instance was originally enabled. The primary Region cannot be removed.

    • Regions (list) --

      The list of Regions enabled in the IAM Identity Center instance, including Regions with ACTIVE, ADDING, or REMOVING status.

      • (dict) --

        Contains information about an enabled Region of an IAM Identity Center instance, including the Region name, status, date added, and whether it is the primary Region.

        • RegionName (string) --

          The Amazon Web Services Region name.

        • Status (string) --

          The current status of the Region. Valid values are ACTIVE (Region is operational), ADDING (Region extension workflow is in progress), or REMOVING (Region removal workflow is in progress).

        • AddedDate (datetime) --

          The timestamp when the Region was added to the IAM Identity Center instance. For the primary Region, this is the instance creation time.

        • IsPrimaryRegion (boolean) --

          Indicates whether this is the primary Region where the IAM Identity Center instance was originally enabled. The primary Region cannot be removed.

    • EncryptionConfigurationDetails (dict) --

      Contains the encryption configuration for your IAM Identity Center instance, including the encryption status, KMS key type, and KMS key ARN.

      • KeyType (string) --

        The type of KMS key used for encryption.

      • KmsKeyArn (string) --

        The ARN of the KMS key currently used to encrypt data in your IAM Identity Center instance.

      • EncryptionStatus (string) --

        The current status of encryption configuration.

      • EncryptionStatusReason (string) --

        Provides additional context about the current encryption status. This field is particularly useful when the encryption status is UPDATE_FAILED. When encryption configuration update fails, this field contains information about the cause, which may include KMS key access issues, key not found errors, invalid key configuration, key in an invalid state, or a disabled key.

    • PermissionSetsEnabled (boolean) --

      Indicates whether permission sets are enabled for this Identity Center instance.

ListInstances (updated) Link ¶
Changes (response)
{'Instances': {'IdentityStoreArn': 'string'}}

Lists the details of the organization and account instances of IAM Identity Center that were created in or visible to the account calling this API.

See also: AWS API Documentation

Request Syntax

client.list_instances(
    MaxResults=123,
    NextToken='string'
)
type MaxResults:

integer

param MaxResults:

The maximum number of results to display for the instance.

type NextToken:

string

param NextToken:

The pagination token for the list API. Initially the value is null. Use the output of previous API calls to make subsequent calls.

rtype:

dict

returns:

Response Syntax

{
    'Instances': [
        {
            'InstanceArn': 'string',
            'IdentityStoreId': 'string',
            'IdentityStoreArn': 'string',
            'OwnerAccountId': 'string',
            'Name': 'string',
            'CreatedDate': datetime(2015, 1, 1),
            'Status': 'CREATE_IN_PROGRESS'|'CREATE_FAILED'|'DELETE_IN_PROGRESS'|'ACTIVE',
            'StatusReason': 'string',
            'PrimaryRegion': 'string',
            'Regions': [
                {
                    'RegionName': 'string',
                    'Status': 'ACTIVE'|'ADDING'|'REMOVING',
                    'AddedDate': datetime(2015, 1, 1),
                    'IsPrimaryRegion': True|False
                },
            ]
        },
    ],
    'NextToken': 'string'
}

Response Structure

  • (dict) --

    • Instances (list) --

      Lists the IAM Identity Center instances that the caller has access to.

      • (dict) --

        Provides information about the IAM Identity Center instance.

        • InstanceArn (string) --

          The ARN of the Identity Center instance under which the operation will be executed. For more information about ARNs, see Amazon Resource Names (ARNs) and Amazon Web Services Service Namespaces in the Amazon Web Services General Reference.

        • IdentityStoreId (string) --

          The identifier of the identity store that is connected to the Identity Center instance.

        • IdentityStoreArn (string) --

          The ARN of the identity store that is connected to the Identity Center instance.

        • OwnerAccountId (string) --

          The Amazon Web Services account ID number of the owner of the Identity Center instance.

        • Name (string) --

          The name of the Identity Center instance.

        • CreatedDate (datetime) --

          The date and time that the Identity Center instance was created.

        • Status (string) --

          The current status of this Identity Center instance.

        • StatusReason (string) --

          Provides additional context about the current status of the IAM Identity Center instance. This field is particularly useful when an instance is in a non-ACTIVE state, such as CREATE_FAILED. When an instance creation fails, this field contains information about the cause, which may include issues with KMS key configuration or insufficient permissions.

        • PrimaryRegion (string) --

          The primary Region where the IAM Identity Center instance was originally enabled. The primary Region cannot be removed.

        • Regions (list) --

          The list of Regions enabled in the IAM Identity Center instance, including Regions with ACTIVE, ADDING, or REMOVING status.

          • (dict) --

            Contains information about an enabled Region of an IAM Identity Center instance, including the Region name, status, date added, and whether it is the primary Region.

            • RegionName (string) --

              The Amazon Web Services Region name.

            • Status (string) --

              The current status of the Region. Valid values are ACTIVE (Region is operational), ADDING (Region extension workflow is in progress), or REMOVING (Region removal workflow is in progress).

            • AddedDate (datetime) --

              The timestamp when the Region was added to the IAM Identity Center instance. For the primary Region, this is the instance creation time.

            • IsPrimaryRegion (boolean) --

              Indicates whether this is the primary Region where the IAM Identity Center instance was originally enabled. The primary Region cannot be removed.

    • NextToken (string) --

      The pagination token for the list API. Initially the value is null. Use the output of previous API calls to make subsequent calls.