AWS IAM Identity Center
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for AWS IAM Identity Center rules that match the service but not a specific eventName. | N | N |
| Associate | Associates a directory with an IAM Identity Center instance to use it as the identity source. | N | Y |
| Disassociate | Disassociates a directory from an IAM Identity Center instance, removing it as the identity source. | N | Y |
| Add | Adds a Region to an IAM Identity Center instance. | N | N |
| Attach | Attaches the specified customer managed policy to the specified PermissionSet. | N | N |
| Attach | Attaches an Amazon Web Services managed policy ARN to a permission set. | N | N |
| Create | Assigns access to a principal for a specified Amazon Web Services account using a specified permission set. | Y | N |
| Create | Creates an OAuth 2.0 customer managed application in IAM Identity Center for the given application provider. | Y | N |
| Create | Grant application access to a user or group. | N | N |
| Create | Creates an instance of IAM Identity Center for a standalone Amazon Web Services account that is not managed by Organizations or a member Amazon Web Services account in an organization. | Y | N |
| Create | Enables the attributes-based access control (ABAC) feature for the specified IAM Identity Center instance. | Y | N |
| Create | Creates a permission set within a specified IAM Identity Center instance. | Y | N |
| Create | Creates a connection to a trusted token issuer in an instance of IAM Identity Center. | Y | N |
| Delete | Deletes a principal's access from a specified Amazon Web Services account using a specified permission set. | Y | N |
| Delete | Deletes the association with the application. | Y | N |
| Delete | Deletes an IAM Identity Center access scope from an application. | Y | N |
| Delete | Revoke application access to an application by deleting application assignments for a user or group. | Y | N |
| Delete | Deletes an authentication method from an application. | Y | N |
| Delete | Deletes a grant from an application. | Y | N |
| Delete | Deletes the inline policy from a specified permission set. | Y | N |
| Delete | Deletes the instance of IAM Identity Center. | Y | N |
| Delete | Disables the attributes-based access control (ABAC) feature for the specified IAM Identity Center instance and deletes all of the attribute mappings that have been configured. | Y | N |
| Delete | Deletes the permissions boundary from a specified PermissionSet. | Y | N |
| Delete | Deletes the specified permission set. | Y | N |
| Delete | Deletes a trusted token issuer configuration from an instance of IAM Identity Center. | Y | N |
| Describe | Describes the status of the assignment creation request. | Y | N |
| Describe | Describes the status of the assignment deletion request. | Y | N |
| Describe | Retrieves the details of an application associated with an instance of IAM Identity Center. | Y | N |
| Describe | Retrieves a direct assignment of a user or group to an application. | Y | N |
| Describe | Retrieves details about a provider that can be used to connect an Amazon Web Services managed application or customer managed application to IAM Identity Center. | Y | N |
| Describe | Returns the details of an instance of IAM Identity Center. | Y | N |
| Describe | Returns the list of IAM Identity Center identity store attributes that have been configured to work with attributes-based access control (ABAC) for the specified IAM Identity Center instance. | Y | N |
| Describe | Gets the details of the permission set. | Y | N |
| Describe | Describes the status for the given permission set provisioning request. | Y | N |
| Describe | Retrieves details about a specific Region enabled in an IAM Identity Center instance. | Y | N |
| Describe | Retrieves details about a trusted token issuer configuration stored in an instance of IAM Identity Center. | Y | N |
| Detach | Detaches the specified customer managed policy from the specified PermissionSet. | Y | N |
| Detach | Detaches the attached Amazon Web Services managed policy ARN from the specified permission set. | Y | N |
| Get | Retrieves the authorized targets for an IAM Identity Center access scope for an application. | Y | N |
| Get | Retrieves the configuration of PutApplicationAssignmentConfiguration. | Y | N |
| Get | Retrieves details about an authentication method used by an application. | Y | N |
| Get | Retrieves details about an application grant. | Y | N |
| Get | Retrieves the session configuration for an application in IAM Identity Center. | Y | N |
| Get | Obtains the inline policy assigned to the permission set. | Y | N |
| Get | Obtains the permissions boundary for a specified PermissionSet. | Y | N |
| List | Lists the status of the Amazon Web Services account assignment creation requests for a specified IAM Identity Center instance. | Y | N |
| List | Lists the status of the Amazon Web Services account assignment deletion requests for a specified IAM Identity Center instance. | Y | N |
| List | Lists the assignee of the specified Amazon Web Services account with the specified permission set. | Y | N |
| List | Retrieves a list of the IAM Identity Center associated Amazon Web Services accounts that the principal has access to. | Y | N |
| List | Lists all the Amazon Web Services accounts where the specified permission set is provisioned. | Y | N |
| List | Lists the access scopes and authorized targets associated with an application. | Y | N |
| List | Lists Amazon Web Services account users that are assigned to an application. | Y | N |
| List | Lists the applications to which a specified principal is assigned. | Y | N |
| List | Lists all of the authentication methods supported by the specified application. | Y | N |
| List | List the grants associated with an application. | Y | N |
| List | Lists the application providers configured in the IAM Identity Center identity store. | Y | N |
| List | Lists all applications associated with the instance of IAM Identity Center. | Y | Y |
| List | Lists all customer managed policies attached to a specified PermissionSet. | Y | N |
| List | Lists the details of the organization and account instances of IAM Identity Center that were created in or visible to the account calling this API. | Y | N |
| List | Lists the Amazon Web Services managed policy that is attached to a specified permission set. | Y | N |
| List | Lists the status of the permission set provisioning requests for a specified IAM Identity Center instance. | Y | N |
| List | Lists the PermissionSets in an IAM Identity Center instance. | Y | N |
| List | Lists all the permission sets that are provisioned to a specified Amazon Web Services account. | Y | N |
| List | Lists all enabled Regions of an IAM Identity Center instance, including those that are being added or removed. | Y | N |
| List | Lists the tags that are attached to a specified resource. | Y | N |
| List | Lists all the trusted token issuers configured in an instance of IAM Identity Center. | Y | N |
| Provision | The process by which a specified permission set is provisioned to the specified target. | N | N |
| Put | Adds or updates the list of authorized targets for an IAM Identity Center access scope for an application. | N | N |
| Put | Configure how users gain access to an application. | N | N |
| Put | Adds or updates an authentication method for an application. | N | N |
| Put | Creates a configuration for an application to use grants. | N | N |
| Put | Updates the session configuration for an application in IAM Identity Center. | N | N |
| Put | Attaches an inline policy to a permission set. | N | N |
| Put | Attaches an Amazon Web Services managed or customer managed policy to the specified PermissionSet as a permissions boundary. | N | N |
| Remove | Removes an additional Region from an IAM Identity Center instance. | Y | N |
| Tag | Associates a set of tags with a specified resource. | N | N |
| Untag | Disassociates a set of tags from a specified resource. | Y | N |
| Update | Updates application properties. | Y | N |
| Update | Update the details for the instance of IAM Identity Center that is owned by the Amazon Web Services account. | Y | N |
| Update | Updates the IAM Identity Center identity store attributes that you can use with the IAM Identity Center instance for attributes-based access control (ABAC). | Y | N |
| Update | Updates an existing permission set. | Y | N |
| Update | Updates the name of the trusted token issuer, or the path of a source attribute or destination attribute for a trusted token issuer configuration. | Y | N |
| Authenticate | Authenticate recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | Y |
| Create | CreateToken recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | Y |
| Describe | DescribeRegisteredRegions recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Federate | Federate recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetRoleCredentials recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetSsoConfiguration recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetSSOStatus recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListAccountRoles recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListDirectoryAssociations recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListProfilesForApplication recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Logout | Logout recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
any: AWS IAM Identity Center (catch-all)
#Description
Catch-all entry for AWS IAM Identity Center rules that match the service but not a specific eventName.
AssociateDirectory
#Description
Associates a directory with an IAM Identity Center instance to use it as the identity source.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1556↳ also matches DisassociateDirectory
DisassociateDirectory
#Description
Disassociates a directory from an IAM Identity Center instance, removing it as the identity source.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1556↳ also matches AssociateDirectory
AddRegion
#Description
Adds a Region to an IAM Identity Center instance.
AttachCustomerManagedPolicyReferenceToPermissionSet
#Description
Attaches the specified customer managed policy to the specified PermissionSet.
AttachManagedPolicyToPermissionSet
#Description
Attaches an Amazon Web Services managed policy ARN to a permission set.
CloudTrail management event, logged by default.
CreateAccountAssignment
#Description
Assigns access to a principal for a specified Amazon Web Services account using a specified permission set.
CloudTrail management event, logged by default.Example CloudTrail Event #
{
"eventVersion": "1.09",
"userIdentity": {
"type": "AssumedRole",
"principalId": "AROA****************:User",
"arn": "arn:aws:sts::123456789012:assumed-role/AWSReservedSSO_AdministratorAccess_2276cacebc31d3eb/AdanAlvarez",
"accountId": "123456789012",
"accessKeyId": "AKIA****************",
"sessionContext": {
"sessionIssuer": {
"type": "Role",
"principalId": "AROA****************:User",
"arn": "arn:aws:iam::123456789012:role/aws-reserved/sso.amazonaws.com/euiso-south-2r/AWSReservedSSO_AdministratorAccess_2276cacebc31d3eb",
"accountId": "123456789012",
"userName": "AWSReservedSSO_AdministratorAccess_2276cacebc31d3eb"
},
"attributes": {
"creationDate": "2025-05-24T14:45:18Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2025-05-24T14:52:07Z",
"eventSource": "sso.amazonaws.com",
"eventName": "CreateAccountAssignment",
"awsRegion": "euiso-south-2r",
"sourceIPAddress": "0.0.0.0",
"userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/0.0.0.0 Safari/537.36",
"requestParameters": {
"instanceArn": "arn:aws:sso:::instance/ssoins-66846d02039d7f57",
"targetId": "760507577735",
"targetType": "AWS_ACCOUNT",
"permissionSetArn": "arn:aws:sso:::permissionSet/ssoins-66846d02039d7f57/ps-cc3ba8d6d6642c51",
"principalType": "GROUP",
"principalId": "AROA****************:User"
},
"responseElements": {
"accountAssignmentCreationStatus": {
"status": "IN_PROGRESS",
"requestId": "9987b8b8-20f7-4a42-85a9-17c48c76a74b",
"targetId": "760507577735",
"targetType": "AWS_ACCOUNT",
"permissionSetArn": "arn:aws:sso:::permissionSet/ssoins-66846d02039d7f57/ps-cc3ba8d6d6642c51",
"principalType": "GROUP",
"principalId": "AROA****************:User"
}
},
"requestID": "9987b8b8-20f7-4a42-85a9-17c48c76a74b",
"eventID": "7a0067f3-5a91-4116-ab94-e497b06054ae",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "123456789012",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.euiso-south-2r.amazonaws.com"
},
"sessionCredentialFromConsole": "true"
}
References #
CreateApplication
#Description
Creates an OAuth 2.0 customer managed application in IAM Identity Center for the given application provider.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "ValidationException",
"errorMessage": "The application provider with arn 'arn:aws:sso::aws:applicationProvider/app-541391d7d89edb80' is not supported for this action.",
"eventCategory": "Management",
"eventID": "6f3a4c0b-db06-4b1d-ad58-45a8b63e32a3",
"eventName": "CreateApplication",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T21:50:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "fc1843c8-b450-448c-ac26-6e1dcfd27f3d",
"requestParameters": null,
"resources": [
{
"ARN": "arn:aws:sso:::instance/ssoins-722375f143f78333",
"accountId": "123456789012",
"type": "AWS::SSO::Instance"
},
{
"ARN": "arn:aws:sso::aws:applicationProvider/catalog/Statuspage",
"accountId": "123456789012",
"type": "AWS::SSO::ApplicationProvider"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateApplicationAssignment
#Description
Grant application access to a user or group.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "1dcf2125-f12c-35fb-9875-d84df13ff788",
"eventSource": "sso.amazonaws.com",
"eventName": "CreateApplicationAssignment",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "1b814a1c-6a6e-4d12-ac4b-f486c6d1c685",
"userAgent": "q.amazonaws.com",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::SSO::Instance",
"ARN": "arn:aws:sso:::EXAMPLE"
},
{
"accountId": "123456789012",
"type": "AWS::SSO::Application",
"ARN": "arn:aws:sso::123456789012:application/EXAMPLE"
}
]
}
CreateInstance
#Description
Creates an instance of IAM Identity Center for a standalone Amazon Web Services account that is not managed by Organizations or a member Amazon Web Services account in an organization.
CloudTrail management event, logged by default.Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationConfigurationDefaults": {
"allowedMfaTypes": [
"TOTP",
"WEBAUTHN"
],
"mfaMode": "CONTEXT_AWARE",
"noMfaSignInBehavior": "ALLOWED_WITH_ENROLLMENT",
"noPasswordSignInBehavior": "BLOCKED"
},
"SessionConfigurationDefaults": {
"extendedSessionEnabledAppProviders": [
"codewhisperer"
],
"sessionDuration": "PT8H"
}
},
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "d14606dd-36a2-48e7-a20c-f8cc8aeb6ad4",
"eventName": "CreateInstance",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T21:50:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "1e2db816-ec40-4ae3-be88-871f719f38f9",
"requestParameters": {
"clientToken": "7777c2d8-02a9-46e7-b8de-2eea7d616c45",
"name": "dwfix-sso-sample",
"tags": [
{
"key": "dw-teardown",
"value": "true"
}
]
},
"responseElements": {
"instanceArn": "arn:aws:sso:::instance/ssoins-722375f143f78333"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateInstanceAccessControlAttributeConfiguration
#Description
Enables the attributes-based access control (ABAC) feature for the specified IAM Identity Center instance.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "ValidationException",
"errorMessage": "This operation is not supported for account instances of IAM Identity Center.",
"eventCategory": "Management",
"eventID": "0a0ee9b5-92b5-49c5-86b4-42b1f21c7dfd",
"eventName": "CreateInstanceAccessControlAttributeConfiguration",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T21:50:20Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7a9d9019-5a18-4462-875f-6c5941e69576",
"requestParameters": null,
"resources": [
{
"ARN": "arn:aws:sso:::instance/ssoins-722375f143f78333",
"accountId": "123456789012",
"type": "AWS::SSO::Instance"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreatePermissionSet
#Description
Creates a permission set within a specified IAM Identity Center instance.
CloudTrail management event, logged by default.Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "ValidationException",
"errorMessage": "This operation is not supported for account instances of IAM Identity Center.",
"eventCategory": "Management",
"eventID": "f36f91e7-9d93-48b8-8c38-5742b2a4e66d",
"eventName": "CreatePermissionSet",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T21:50:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2f04300f-4307-4c91-9df9-5bb607c86e6f",
"requestParameters": null,
"resources": [
{
"ARN": "arn:aws:sso:::instance/ssoins-722375f143f78333",
"accountId": "123456789012",
"type": "AWS::SSO::Instance"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateTrustedTokenIssuer
#Description
Creates a connection to a trusted token issuer in an instance of IAM Identity Center.
CloudTrail management event, logged by default.Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'trustedTokenIssuerConfiguration.oidcJwtConfiguration.identityStoreAttributePath' failed to satisfy constraint: Member must satisfy regular expression pattern: \\p{L}+(?:\\.\\p{L}+){0,2}",
"eventCategory": "Management",
"eventID": "d3d97d48-cacb-4c1b-aa9c-0dfe0c532816",
"eventName": "CreateTrustedTokenIssuer",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T21:50:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "465369ad-aee4-4c9f-89a1-973385476e9c",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteAccountAssignment
#Description
Deletes a principal's access from a specified Amazon Web Services account using a specified permission set.
CloudTrail management event, logged by default.Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'targetId' failed to satisfy constraint: Member must satisfy regular expression pattern: \\d{12}; Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'principalId' failed to satisfy constraint: Member must satisfy regular expression pattern: ([0-9a-f]{10}-|)[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "0a7da0f8-2a06-4a0f-9979-f9f86636a9e4",
"eventName": "DeleteAccountAssignment",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T19:26:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7d80020c-2435-48d2-88ae-3d64ce5ba4c4",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteApplication
#Description
Deletes the association with the application.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
"eventCategory": "Management",
"eventID": "935860dc-e670-4032-a274-9cd9f3d104a6",
"eventName": "DeleteApplication",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T19:26:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "0153f046-45a2-48e8-8168-9e52c1e14ce4",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteApplicationAccessScope
#Description
Deletes an IAM Identity Center access scope from an application.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'scope' failed to satisfy constraint: Member must satisfy regular expression pattern: ([A-Za-z0-9_]{1,50})(:[A-Za-z0-9_]{1,50}){0,1}(:[A-Za-z0-9_]{1,50}){0,1}; Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
"eventCategory": "Management",
"eventID": "b8228359-b44d-47cf-a91a-1f601b33c3d3",
"eventName": "DeleteApplicationAccessScope",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T19:26:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "31ff0dc3-c70f-41d3-881b-8049db9a9b12",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteApplicationAssignment
#Description
Revoke application access to an application by deleting application assignments for a user or group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}; Value of input 'principalId' failed to satisfy constraint: Member must satisfy regular expression pattern: ([0-9a-f]{10}-|)[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}",
"eventCategory": "Management",
"eventID": "b61fc3d5-ce0b-4c55-ad7d-af3907715778",
"eventName": "DeleteApplicationAssignment",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T19:26:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "fb4254ed-67c7-45ba-9fcf-ae8f2307a568",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteApplicationAuthenticationMethod
#Description
Deletes an authentication method from an application.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
"eventCategory": "Management",
"eventID": "0464b722-4f76-4a59-96fb-3a5a70b8c8f4",
"eventName": "DeleteApplicationAuthenticationMethod",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T19:26:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ba4bc3de-277f-4750-83cf-841603d7d134",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteApplicationGrant
#Description
Deletes a grant from an application.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
"eventCategory": "Management",
"eventID": "dbb7fceb-c8fc-40f4-b522-ed0aa42cff32",
"eventName": "DeleteApplicationGrant",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T19:26:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f712fdb2-790d-445b-9efe-b1dafbc2c358",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteInlinePolicyFromPermissionSet
#Description
Deletes the inline policy from a specified permission set.
CloudTrail management event, logged by default.Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "78bda4de-ba5d-4710-bdb8-d5fcc19c3fd9",
"eventName": "DeleteInlinePolicyFromPermissionSet",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T19:26:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "fdf23a28-2200-4fb7-94f8-a081629a70b8",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteInstance
#Description
Deletes the instance of IAM Identity Center.
CloudTrail management event, logged by default.Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "fdd5b72c-926c-4540-b9f4-216b5b4a3d4d",
"eventName": "DeleteInstance",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T19:26:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2cd4caee-626c-4cb3-8880-56374d8ab208",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteInstanceAccessControlAttributeConfiguration
#Description
Disables the attributes-based access control (ABAC) feature for the specified IAM Identity Center instance and deletes all of the attribute mappings that have been configured.
CloudTrail management event, logged by default.Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "2a69f3b2-418c-48c5-bf2c-5b8b0e2eb280",
"eventName": "DeleteInstanceAccessControlAttributeConfiguration",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T19:26:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "33ffd94f-4634-4d6d-a91c-f555868c502c",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeletePermissionsBoundaryFromPermissionSet
#Description
Deletes the permissions boundary from a specified PermissionSet.
CloudTrail management event, logged by default.Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "12eff39e-8b0d-4b90-aa3b-30a1d6a9ea06",
"eventName": "DeletePermissionsBoundaryFromPermissionSet",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T19:26:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "27223b81-3510-445a-bca0-fa9e0a84ba5b",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeletePermissionSet
#Description
Deletes the specified permission set.
CloudTrail management event, logged by default.Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "4d191cd1-f1a1-4566-9035-0eff31adddd2",
"eventName": "DeletePermissionSet",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T19:26:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6ac5048d-5ded-486d-bd36-62262615ea01",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTrustedTokenIssuer
#Description
Deletes a trusted token issuer configuration from an instance of IAM Identity Center.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'trustedTokenIssuerArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:trustedTokenIssuer/(sso)?ins-[a-zA-Z0-9-.]{16}/tti-[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}",
"eventCategory": "Management",
"eventID": "147822d3-ec5d-4097-8ea0-22d59ec269a2",
"eventName": "DeleteTrustedTokenIssuer",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T19:26:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "86471af4-098e-4abc-93d6-fd1c17f6cb88",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeAccountAssignmentCreationStatus
#Description
Describes the status of the assignment creation request.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'accountAssignmentCreationRequestId' failed to satisfy constraint: Member must satisfy regular expression pattern: \\b[0-9a-f]{8}\\b-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-\\b[0-9a-f]{12}\\b; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "016a0e24-a9a8-4005-a658-b48c5807f3d4",
"eventName": "DescribeAccountAssignmentCreationStatus",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "b25378a1-899b-4fe0-813c-88d00bb668f8",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeAccountAssignmentDeletionStatus
#Description
Describes the status of the assignment deletion request.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'accountAssignmentDeletionRequestId' failed to satisfy constraint: Member must satisfy regular expression pattern: \\b[0-9a-f]{8}\\b-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-\\b[0-9a-f]{12}\\b; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "c3bb1987-366e-4f26-86b7-10d4012648b6",
"eventName": "DescribeAccountAssignmentDeletionStatus",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "edea5050-fcb1-4695-a9e6-430d9e029cd4",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeApplication
#Description
Retrieves the details of an application associated with an instance of IAM Identity Center.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
"eventCategory": "Management",
"eventID": "86183a1f-fa11-401b-860e-0e7aebcf50a9",
"eventName": "DescribeApplication",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "14a612f7-d480-45fc-88b0-d37f7a275657",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeApplicationAssignment
#Description
Retrieves a direct assignment of a user or group to an application.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}; Value of input 'principalId' failed to satisfy constraint: Member must satisfy regular expression pattern: ([0-9a-f]{10}-|)[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}",
"eventCategory": "Management",
"eventID": "e4d56aa8-3fc0-4239-8b27-f6c057b632e5",
"eventName": "DescribeApplicationAssignment",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "92c87916-a09d-4afc-8eca-81ff8ac779cd",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeApplicationProvider
#Description
Retrieves details about a provider that can be used to connect an Amazon Web Services managed application or customer managed application to IAM Identity Center.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'applicationProviderArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::aws:applicationProvider/[a-zA-Z0-9-/]+",
"eventCategory": "Management",
"eventID": "b0bcc21b-746d-4466-9fb2-d34d89af4ae5",
"eventName": "DescribeApplicationProvider",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "19e377dc-6187-4a07-a52e-ecd0d3fe9b66",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeInstance
#Description
Returns the details of an instance of IAM Identity Center.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "9e5b0d7d-4d17-4e7a-b900-a3d88030eeac",
"eventName": "DescribeInstance",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "87e9bed0-ced1-41ef-9f67-a82be107a8e0",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeInstanceAccessControlAttributeConfiguration
#Description
Returns the list of IAM Identity Center identity store attributes that have been configured to work with attributes-based access control (ABAC) for the specified IAM Identity Center instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "b16ac8a8-7dcf-41fc-ad36-1c848cac5ff0",
"eventName": "DescribeInstanceAccessControlAttributeConfiguration",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c2ff0ed5-3d46-4451-8989-79e16667ce04",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribePermissionSet
#Description
Gets the details of the permission set.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "d12de061-9982-4673-95f1-9b76a21519c9",
"eventName": "DescribePermissionSet",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "989cd211-a9ef-449a-a38c-2e2ca2ba26d7",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribePermissionSetProvisioningStatus
#Description
Describes the status for the given permission set provisioning request.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'provisionPermissionSetRequestId' failed to satisfy constraint: Member must satisfy regular expression pattern: \\b[0-9a-f]{8}\\b-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-\\b[0-9a-f]{12}\\b; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "3f84a35f-aead-4b43-8efb-2fdce9fdd110",
"eventName": "DescribePermissionSetProvisioningStatus",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "81536275-fe77-433e-b925-2b7e34aaf1e9",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeRegion
#Description
Retrieves details about a specific Region enabled in an IAM Identity Center instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'regionName' failed to satisfy constraint: Member must satisfy regular expression pattern: ([a-z]+-){2,3}\\d; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "1128d804-f0dd-4fb7-ab77-eeb600f7b3b1",
"eventName": "DescribeRegion",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c2b97f0c-2bc1-42ad-bfe9-c9ba09e34787",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeTrustedTokenIssuer
#Description
Retrieves details about a trusted token issuer configuration stored in an instance of IAM Identity Center.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'trustedTokenIssuerArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:trustedTokenIssuer/(sso)?ins-[a-zA-Z0-9-.]{16}/tti-[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}",
"eventCategory": "Management",
"eventID": "679d0417-850e-4a94-8cf9-75ae7e313369",
"eventName": "DescribeTrustedTokenIssuer",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "f900bd52-0501-46b6-ad28-255dad30c69e",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DetachCustomerManagedPolicyReferenceFromPermissionSet
#Description
Detaches the specified customer managed policy from the specified PermissionSet.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "d4fcb2e3-bf98-4d5b-96a0-03ad4c973b8a",
"eventName": "DetachCustomerManagedPolicyReferenceFromPermissionSet",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T19:26:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8e82f77f-c58c-42d0-9924-dc595a529de7",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DetachManagedPolicyFromPermissionSet
#Description
Detaches the attached Amazon Web Services managed policy ARN from the specified permission set.
CloudTrail management event, logged by default.Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}; Value of input 'managedPolicyArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:iam::aws:policy((/[A-Za-z0-9\\.,\\+@=_-]+)*)/([A-Za-z0-9\\.,\\+=@_-]+)",
"eventCategory": "Management",
"eventID": "29434892-0b1c-4f6a-8dde-48b16e05edae",
"eventName": "DetachManagedPolicyFromPermissionSet",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T19:26:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c178747a-5ab2-40e5-876d-62aa4357d5c8",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetApplicationAccessScope
#Description
Retrieves the authorized targets for an IAM Identity Center access scope for an application.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'scope' failed to satisfy constraint: Member must satisfy regular expression pattern: ([A-Za-z0-9_]{1,50})(:[A-Za-z0-9_]{1,50}){0,1}(:[A-Za-z0-9_]{1,50}){0,1}; Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
"eventCategory": "Management",
"eventID": "68e2d2db-537b-4894-b661-bd47e1a3ac43",
"eventName": "GetApplicationAccessScope",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "9c4618a7-f321-4024-b8ca-3d236c361e89",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetApplicationAssignmentConfiguration
#Description
Retrieves the configuration of PutApplicationAssignmentConfiguration.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
"eventCategory": "Management",
"eventID": "a6234748-ac0b-446b-ae05-4fe2f4dc028d",
"eventName": "GetApplicationAssignmentConfiguration",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "2c0ae60a-f2f2-4298-94d1-d91568a0659d",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetApplicationAuthenticationMethod
#Description
Retrieves details about an authentication method used by an application.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
"eventCategory": "Management",
"eventID": "79a94fce-7af0-4dcd-8e39-92748c0f63a4",
"eventName": "GetApplicationAuthenticationMethod",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "47f7356c-3f8e-47a8-ba3b-4e221fa571dc",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetApplicationGrant
#Description
Retrieves details about an application grant.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
"eventCategory": "Management",
"eventID": "35ac0d0b-3a57-4e87-9402-47484a102ee3",
"eventName": "GetApplicationGrant",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "6f812506-759e-4f9c-987b-3b077ac2f1fa",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetApplicationSessionConfiguration
#Description
Retrieves the session configuration for an application in IAM Identity Center.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
"eventCategory": "Management",
"eventID": "431258c9-c2b8-40d6-8c47-ff7a304da706",
"eventName": "GetApplicationSessionConfiguration",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "287aeda6-1c66-4960-bfb4-fd9c04c3e1a6",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetInlinePolicyForPermissionSet
#Description
Obtains the inline policy assigned to the permission set.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "be503feb-4869-4132-8568-c42b207f1ac6",
"eventName": "GetInlinePolicyForPermissionSet",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "b84365a3-ee8f-43f8-8454-804a9c0adaa5",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetPermissionsBoundaryForPermissionSet
#Description
Obtains the permissions boundary for a specified PermissionSet.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "97a3a36c-1ed9-4ff4-b83e-27cb048632c2",
"eventName": "GetPermissionsBoundaryForPermissionSet",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c4036cdd-1528-425f-9e29-fe5bad909f4d",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListAccountAssignmentCreationStatus
#Description
Lists the status of the Amazon Web Services account assignment creation requests for a specified IAM Identity Center instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "afa72cf8-4507-4cf6-924a-f58d1fa44f0d",
"eventName": "ListAccountAssignmentCreationStatus",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "bfa290c5-6617-42b9-af62-fdb92517ab2e",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListAccountAssignmentDeletionStatus
#Description
Lists the status of the Amazon Web Services account assignment deletion requests for a specified IAM Identity Center instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "e4c4aa51-2b6d-4267-abd7-0b856b6763b2",
"eventName": "ListAccountAssignmentDeletionStatus",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "344a58d1-7856-4a5a-8fb8-5267148ac09e",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListAccountAssignments
#Description
Lists the assignee of the specified Amazon Web Services account with the specified permission set.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'accountId' failed to satisfy constraint: Member must satisfy regular expression pattern: \\d{12}; Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "e013cad4-04b2-4c60-ac4e-be19b6131bbc",
"eventName": "ListAccountAssignments",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "64475bef-0eb2-4d33-b1ad-12aa9af52adb",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListAccountAssignmentsForPrincipal
#Description
Retrieves a list of the IAM Identity Center associated Amazon Web Services accounts that the principal has access to.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'principalId' failed to satisfy constraint: Member must satisfy regular expression pattern: ([0-9a-f]{10}-|)[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "76952ead-da8a-4f3a-8e69-f156121d167f",
"eventName": "ListAccountAssignmentsForPrincipal",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "f613e680-c412-4355-adac-4af4b55b5ebd",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListAccountsForProvisionedPermissionSet
#Description
Lists all the Amazon Web Services accounts where the specified permission set is provisioned.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "a0b8844d-2293-402e-937c-2337376bb695",
"eventName": "ListAccountsForProvisionedPermissionSet",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "1720e63f-d35c-4bf9-a231-e78431daaafb",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListApplicationAccessScopes
#Description
Lists the access scopes and authorized targets associated with an application.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
"eventCategory": "Management",
"eventID": "593fa577-55d5-4da4-bd9a-e67cda644a5c",
"eventName": "ListApplicationAccessScopes",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "3ed69112-e2d9-4d85-bb37-49944e61848d",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListApplicationAssignments
#Description
Lists Amazon Web Services account users that are assigned to an application.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
"eventCategory": "Management",
"eventID": "2fdfc090-de4f-4929-a6a4-cfb4ad2a64f3",
"eventName": "ListApplicationAssignments",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "ac4d0754-cfc5-4e5f-8c2d-f49a188ae6f5",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListApplicationAssignmentsForPrincipal
#Description
Lists the applications to which a specified principal is assigned.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'principalId' failed to satisfy constraint: Member must satisfy regular expression pattern: ([0-9a-f]{10}-|)[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "3a931b5d-5f8e-413b-89fb-f3b08be9407a",
"eventName": "ListApplicationAssignmentsForPrincipal",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "bda809bd-8f89-47ce-a3c9-f35ae2d02088",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListApplicationAuthenticationMethods
#Description
Lists all of the authentication methods supported by the specified application.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
"eventCategory": "Management",
"eventID": "ae7512a9-b79b-4b3d-9e10-e46dd553b05c",
"eventName": "ListApplicationAuthenticationMethods",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "a2bf940e-3124-48e4-8f65-f33fce3b165f",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListApplicationGrants
#Description
List the grants associated with an application.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
"eventCategory": "Management",
"eventID": "6115e575-2fc9-462b-bb44-330609f292fb",
"eventName": "ListApplicationGrants",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c2e9aa12-c858-448f-8bc6-5378ad51a180",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListApplicationProviders
#Description
Lists the application providers configured in the IAM Identity Center identity store.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "eb4ea434-6e93-497f-961f-afe0cff48a8d",
"eventName": "ListApplicationProviders",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:32:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "0f8ceaad-3cb9-427e-998d-47e709008141",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListApplications
#Description
Lists all applications associated with the instance of IAM Identity Center.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "7aa5c00b-fe53-4eba-8490-59c4ebd53890",
"eventName": "ListApplications",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "8be5cbd8-fbe0-4c4f-a4c1-9c9b3ad9c5e1",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
ListCustomerManagedPolicyReferencesInPermissionSet
#Description
Lists all customer managed policies attached to a specified PermissionSet.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "7b3c914d-e12f-4b5b-924c-6f0f95bbf7b4",
"eventName": "ListCustomerManagedPolicyReferencesInPermissionSet",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c169413d-45c2-4044-9cc5-2cd64721a94f",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListInstances
#Description
Lists the details of the organization and account instances of IAM Identity Center that were created in or visible to the account calling this API.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "3a3c99ad-4495-4ab2-a5a5-b3058c8c7587",
"eventName": "ListInstances",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:32:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "3f1879fa-deb2-4739-9f10-bafbb1071bdb",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListManagedPoliciesInPermissionSet
#Description
Lists the Amazon Web Services managed policy that is attached to a specified permission set.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "9178b202-7d57-479f-8744-d3a473bb04a0",
"eventName": "ListManagedPoliciesInPermissionSet",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "0e8e3c5d-dcb4-4185-8749-7f550ef45679",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListPermissionSetProvisioningStatus
#Description
Lists the status of the permission set provisioning requests for a specified IAM Identity Center instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "a99c254d-393d-4613-be22-fb0b66e50411",
"eventName": "ListPermissionSetProvisioningStatus",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "8f4f3ad7-74ed-4644-88e3-73e0a7952c14",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListPermissionSets
#Description
Lists the PermissionSets in an IAM Identity Center instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "92b7a8dd-61ce-4fb8-a36f-62ac10835bf9",
"eventName": "ListPermissionSets",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "afd690a7-0227-418a-8d0d-2e4022d5f149",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListPermissionSetsProvisionedToAccount
#Description
Lists all the permission sets that are provisioned to a specified Amazon Web Services account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'accountId' failed to satisfy constraint: Member must satisfy regular expression pattern: \\d{12}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "428e40aa-917a-4c9e-8a85-979cf9a74024",
"eventName": "ListPermissionSetsProvisionedToAccount",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "531a8b55-d443-4155-9667-bbe8d2480aa9",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListRegions
#Description
Lists all enabled Regions of an IAM Identity Center instance, including those that are being added or removed.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "600b7a8a-0319-4d29-9c7e-5eff0077bc0d",
"eventName": "ListRegions",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "64db2b0b-8c68-43c8-b137-7cb0f6d3d71e",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListTrustedTokenIssuers
#Description
Lists all the trusted token issuers configured in an instance of IAM Identity Center.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "3488ce2a-d21d-4095-8a08-a9fddc3f3a82",
"eventName": "ListTrustedTokenIssuers",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T18:46:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "ad0664de-e0a7-427c-8ae9-da0177685722",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ProvisionPermissionSet
#Description
The process by which a specified permission set is provisioned to the specified target.
PutApplicationAccessScope
#Description
Adds or updates the list of authorized targets for an IAM Identity Center access scope for an application.
PutApplicationAssignmentConfiguration
#Description
Configure how users gain access to an application.
PutApplicationAuthenticationMethod
#Description
Adds or updates an authentication method for an application.
PutApplicationGrant
#Description
Creates a configuration for an application to use grants.
PutApplicationSessionConfiguration
#Description
Updates the session configuration for an application in IAM Identity Center.
PutInlinePolicyToPermissionSet
#Description
Attaches an inline policy to a permission set.
CloudTrail management event, logged by default.
PutPermissionsBoundaryToPermissionSet
#Description
Attaches an Amazon Web Services managed or customer managed policy to the specified PermissionSet as a permissions boundary.
RemoveRegion
#Description
Removes an additional Region from an IAM Identity Center instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'regionName' failed to satisfy constraint: Member must satisfy regular expression pattern: ([a-z]+-){2,3}\\d; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "ee8316ec-4288-4ace-af4b-9c656a97ff53",
"eventName": "RemoveRegion",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T19:26:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "cb21abc1-b978-49ab-b571-79f8931b455b",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
TagResource
#Description
Associates a set of tags with a specified resource.
UntagResource
#Description
Disassociates a set of tags from a specified resource.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'resourceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::((:instance/(sso)?ins-[a-zA-Z0-9-.]{16})|(:permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16})|(\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16})|(\\d{12}:trustedTokenIssuer/(sso)?ins-[a-zA-Z0-9-.]{16}/tti-[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}))",
"eventCategory": "Management",
"eventID": "c5bcd3f8-4f04-4cf2-bf8d-2a8073809cae",
"eventName": "UntagResource",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T19:26:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6e08ccb1-eb69-4a0b-b6a4-c5e531ccad45",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateApplication
#Description
Updates application properties.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
"eventCategory": "Management",
"eventID": "88ab7396-fa5a-426c-bdf1-ec1b2437a9e4",
"eventName": "UpdateApplication",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T19:26:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4ed52d46-0df7-4b0e-b21e-f916a7d9d31e",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateInstance
#Description
Update the details for the instance of IAM Identity Center that is owned by the Amazon Web Services account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "7e2190cc-5ee5-4bd4-a169-29521bf481a0",
"eventName": "UpdateInstance",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T19:26:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "757e1bf6-f8cb-47c8-8356-6478e6d8e339",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateInstanceAccessControlAttributeConfiguration
#Description
Updates the IAM Identity Center identity store attributes that you can use with the IAM Identity Center instance for attributes-based access control (ABAC).
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "8e9bbaca-f291-4ba8-a8e7-5723ddea241a",
"eventName": "UpdateInstanceAccessControlAttributeConfiguration",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T19:26:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "19ae9415-6a28-4e92-a63d-8fd234a7b18f",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdatePermissionSet
#Description
Updates an existing permission set.
CloudTrail management event, logged by default.Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
"eventCategory": "Management",
"eventID": "eef905d5-df70-4abd-8d3f-30234dc0d71f",
"eventName": "UpdatePermissionSet",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T19:26:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "0f3f1d86-6d12-45b3-b33a-f09bba9a4318",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateTrustedTokenIssuer
#Description
Updates the name of the trusted token issuer, or the path of a source attribute or destination attribute for a trusted token issuer configuration.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Value of input 'trustedTokenIssuerArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:trustedTokenIssuer/(sso)?ins-[a-zA-Z0-9-.]{16}/tti-[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}",
"eventCategory": "Management",
"eventID": "77a7f467-e857-48be-996d-74a309432ff6",
"eventName": "UpdateTrustedTokenIssuer",
"eventSource": "sso.amazonaws.com",
"eventTime": "2026-06-29T19:26:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "61f8af88-b540-4ad0-8611-24a9ce50879b",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Authenticate
#Description
Authenticate recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "d21742b0-b345-4429-9994-5a91ff17bb0f",
"eventSource": "sso.amazonaws.com",
"eventName": "Authenticate",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": false,
"managementEvent": true,
"requestID": "fd2fc447-34b5-48c9-a22b-ffea5fe653a1",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:153.0) Gecko/20100101 Firefox/153.0"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
CreateToken
#Description
CreateToken recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "f615ca98-490c-4e38-9a8d-9db0379b38ed",
"eventSource": "sso.amazonaws.com",
"eventName": "CreateToken",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "87342727-4500-4289-85d0-f5778b1b83c0",
"userAgent": "aws-cli/2.35.1 md/awscrt#0.32.2 ua/2.1 os/windows#11 md/arch#amd64 lang/python#3.14.5 md/pyimpl#CPython m/Z,E,b cfg/retry-mode#standard md/installer#exe sid/c8a437b6b651 md/prompt#off md/command#sso.login md/sso#auth",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
},
"resources": [
{
"accountId": "123456789012",
"type": "IdentityStoreId",
"ARN": "d-906750297c"
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
DescribeRegisteredRegions
#Description
DescribeRegisteredRegions recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "f250a648-e0b1-4c9b-95c0-4123c60b7a86",
"eventSource": "sso.amazonaws.com",
"eventName": "DescribeRegisteredRegions",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "cd8c8282-8206-4693-b965-6983a8734d96",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:153.0) Gecko/20100101 Firefox/153.0",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-east-1.amazonaws.com"
}
}
Federate
#Description
Federate recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "92fad055-e58b-4209-935d-4b65abc148c0",
"eventSource": "sso.amazonaws.com",
"eventName": "Federate",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": false,
"managementEvent": true,
"requestID": "061a1ab4-3ef9-4e9e-b07c-d53a1c62b395",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
}
GetRoleCredentials
#Description
GetRoleCredentials recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "ff333688-6213-41d9-9663-2282b22efe06",
"eventSource": "sso.amazonaws.com",
"eventName": "GetRoleCredentials",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": true,
"managementEvent": true,
"requestID": "1935edb1-5624-4a3c-baea-ee8c74f3b75d",
"userAgent": "Boto3/1.43.15 md/Botocore#1.43.15 ua/2.1 os/macos#25.5.0 md/arch#arm64 lang/python#3.14.6 md/pyimpl#CPython m/Z,r,D,b cfg/retry-mode#legacy Botocore/1.43.15"
}
GetSsoConfiguration
#Description
GetSsoConfiguration recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "491245de-1ac1-37d6-8a03-bccc9f7e3423",
"eventSource": "sso.amazonaws.com",
"eventName": "GetSsoConfiguration",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "3dcd4bd6-344c-4026-84ef-3954c693f94c",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-east-1.amazonaws.com"
},
"resources": [
{
"accountId": "123456789012",
"type": "AWS::SSO::Instance",
"ARN": "arn:aws:sso:::EXAMPLE"
}
]
}
GetSSOStatus
#Description
GetSSOStatus recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "9964b13f-ca3a-4434-84b9-6523739de1f3",
"eventSource": "sso.amazonaws.com",
"eventName": "GetSSOStatus",
"awsRegion": "us-east-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "40a89441-1a23-42e0-84e9-bb4ef824d482",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-east-2.amazonaws.com"
}
}
ListAccountRoles
#Description
ListAccountRoles recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "7e72f287-205c-42ea-934f-349bb6ba7914",
"eventSource": "sso.amazonaws.com",
"eventName": "ListAccountRoles",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": true,
"managementEvent": true,
"requestID": "e2c2401f-134f-441e-814b-9f2c560e913f",
"userAgent": "aws-cli/2.33.8 md/awscrt#0.29.1 ua/2.1 os/macos#24.6.0 md/arch#arm64 lang/python#3.13.11 md/pyimpl#CPython m/Z,C,b,E cfg/retry-mode#standard md/installer#exe sid/8bfe8f74a9f9 md/prompt#off md/command#configure.sso"
}
ListDirectoryAssociations
#Description
ListDirectoryAssociations recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "d287a4d6-7707-3fbf-b2f5-0c50b5d5e241",
"eventSource": "sso.amazonaws.com",
"eventName": "ListDirectoryAssociations",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "95becf14-c4c2-4eb7-bdc2-cdbf95bbf5d0",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sso.us-east-1.amazonaws.com"
},
"resources": [
{
"accountId": "123456789012",
"type": "AWS::SSO::Instance",
"ARN": "arn:aws:sso:::EXAMPLE"
}
]
}
ListProfilesForApplication
#Description
ListProfilesForApplication recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "bf97d7e2-a93f-456c-973f-83760dba3743",
"eventSource": "sso.amazonaws.com",
"eventName": "ListProfilesForApplication",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": true,
"managementEvent": true,
"requestID": "fcee9ee1-54f5-4894-92d3-9f988c4ce99a",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
}
Logout
#Description
Logout recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "08313f16-0013-4951-bf51-61779c174651",
"eventSource": "sso.amazonaws.com",
"eventName": "Logout",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": false,
"managementEvent": true,
"requestID": "c6de8511-eb36-44eb-8e62-6b50152747c2",
"userAgent": "aws-cli/2.36.8 md/awscrt#0.36.0 ua/2.1 os/macos#25.5.0 md/arch#arm64 lang/python#3.14.6 md/pyimpl#CPython m/E,r,s,Z,b cfg/retry-mode#standard md/installer#source sid/df423b67c71b md/prompt#off md/command#sso.logout"
}