AWS IAM Identity Center

eventNameDescriptionSampleRule
anyCatch-all entry for AWS IAM Identity Center rules that match the service but not a specific eventName.NN
AssociateDirectoryAssociates a directory with an IAM Identity Center instance to use it as the identity source.NY
DisassociateDirectoryDisassociates a directory from an IAM Identity Center instance, removing it as the identity source.NY
AddRegionAdds a Region to an IAM Identity Center instance.NN
AttachCustomerManagedPolicyReferenceToPermissionSetAttaches the specified customer managed policy to the specified PermissionSet.NN
AttachManagedPolicyToPermissionSetAttaches an Amazon Web Services managed policy ARN to a permission set.NN
CreateAccountAssignmentAssigns access to a principal for a specified Amazon Web Services account using a specified permission set.YN
CreateApplicationCreates an OAuth 2.0 customer managed application in IAM Identity Center for the given application provider.YN
CreateApplicationAssignmentGrant application access to a user or group.NN
CreateInstanceCreates an instance of IAM Identity Center for a standalone Amazon Web Services account that is not managed by Organizations or a member Amazon Web Services account in an organization.YN
CreateInstanceAccessControlAttributeConfigurationEnables the attributes-based access control (ABAC) feature for the specified IAM Identity Center instance.YN
CreatePermissionSetCreates a permission set within a specified IAM Identity Center instance.YN
CreateTrustedTokenIssuerCreates a connection to a trusted token issuer in an instance of IAM Identity Center.YN
DeleteAccountAssignmentDeletes a principal's access from a specified Amazon Web Services account using a specified permission set.YN
DeleteApplicationDeletes the association with the application.YN
DeleteApplicationAccessScopeDeletes an IAM Identity Center access scope from an application.YN
DeleteApplicationAssignmentRevoke application access to an application by deleting application assignments for a user or group.YN
DeleteApplicationAuthenticationMethodDeletes an authentication method from an application.YN
DeleteApplicationGrantDeletes a grant from an application.YN
DeleteInlinePolicyFromPermissionSetDeletes the inline policy from a specified permission set.YN
DeleteInstanceDeletes the instance of IAM Identity Center.YN
DeleteInstanceAccessControlAttributeConfigurationDisables the attributes-based access control (ABAC) feature for the specified IAM Identity Center instance and deletes all of the attribute mappings that have been configured.YN
DeletePermissionsBoundaryFromPermissionSetDeletes the permissions boundary from a specified PermissionSet.YN
DeletePermissionSetDeletes the specified permission set.YN
DeleteTrustedTokenIssuerDeletes a trusted token issuer configuration from an instance of IAM Identity Center.YN
DescribeAccountAssignmentCreationStatusDescribes the status of the assignment creation request.YN
DescribeAccountAssignmentDeletionStatusDescribes the status of the assignment deletion request.YN
DescribeApplicationRetrieves the details of an application associated with an instance of IAM Identity Center.YN
DescribeApplicationAssignmentRetrieves a direct assignment of a user or group to an application.YN
DescribeApplicationProviderRetrieves details about a provider that can be used to connect an Amazon Web Services managed application or customer managed application to IAM Identity Center.YN
DescribeInstanceReturns the details of an instance of IAM Identity Center.YN
DescribeInstanceAccessControlAttributeConfigurationReturns the list of IAM Identity Center identity store attributes that have been configured to work with attributes-based access control (ABAC) for the specified IAM Identity Center instance.YN
DescribePermissionSetGets the details of the permission set.YN
DescribePermissionSetProvisioningStatusDescribes the status for the given permission set provisioning request.YN
DescribeRegionRetrieves details about a specific Region enabled in an IAM Identity Center instance.YN
DescribeTrustedTokenIssuerRetrieves details about a trusted token issuer configuration stored in an instance of IAM Identity Center.YN
DetachCustomerManagedPolicyReferenceFromPermissionSetDetaches the specified customer managed policy from the specified PermissionSet.YN
DetachManagedPolicyFromPermissionSetDetaches the attached Amazon Web Services managed policy ARN from the specified permission set.YN
GetApplicationAccessScopeRetrieves the authorized targets for an IAM Identity Center access scope for an application.YN
GetApplicationAssignmentConfigurationRetrieves the configuration of PutApplicationAssignmentConfiguration.YN
GetApplicationAuthenticationMethodRetrieves details about an authentication method used by an application.YN
GetApplicationGrantRetrieves details about an application grant.YN
GetApplicationSessionConfigurationRetrieves the session configuration for an application in IAM Identity Center.YN
GetInlinePolicyForPermissionSetObtains the inline policy assigned to the permission set.YN
GetPermissionsBoundaryForPermissionSetObtains the permissions boundary for a specified PermissionSet.YN
ListAccountAssignmentCreationStatusLists the status of the Amazon Web Services account assignment creation requests for a specified IAM Identity Center instance.YN
ListAccountAssignmentDeletionStatusLists the status of the Amazon Web Services account assignment deletion requests for a specified IAM Identity Center instance.YN
ListAccountAssignmentsLists the assignee of the specified Amazon Web Services account with the specified permission set.YN
ListAccountAssignmentsForPrincipalRetrieves a list of the IAM Identity Center associated Amazon Web Services accounts that the principal has access to.YN
ListAccountsForProvisionedPermissionSetLists all the Amazon Web Services accounts where the specified permission set is provisioned.YN
ListApplicationAccessScopesLists the access scopes and authorized targets associated with an application.YN
ListApplicationAssignmentsLists Amazon Web Services account users that are assigned to an application.YN
ListApplicationAssignmentsForPrincipalLists the applications to which a specified principal is assigned.YN
ListApplicationAuthenticationMethodsLists all of the authentication methods supported by the specified application.YN
ListApplicationGrantsList the grants associated with an application.YN
ListApplicationProvidersLists the application providers configured in the IAM Identity Center identity store.YN
ListApplicationsLists all applications associated with the instance of IAM Identity Center.YY
ListCustomerManagedPolicyReferencesInPermissionSetLists all customer managed policies attached to a specified PermissionSet.YN
ListInstancesLists the details of the organization and account instances of IAM Identity Center that were created in or visible to the account calling this API.YN
ListManagedPoliciesInPermissionSetLists the Amazon Web Services managed policy that is attached to a specified permission set.YN
ListPermissionSetProvisioningStatusLists the status of the permission set provisioning requests for a specified IAM Identity Center instance.YN
ListPermissionSetsLists the PermissionSets in an IAM Identity Center instance.YN
ListPermissionSetsProvisionedToAccountLists all the permission sets that are provisioned to a specified Amazon Web Services account.YN
ListRegionsLists all enabled Regions of an IAM Identity Center instance, including those that are being added or removed.YN
ListTagsForResourceLists the tags that are attached to a specified resource.YN
ListTrustedTokenIssuersLists all the trusted token issuers configured in an instance of IAM Identity Center.YN
ProvisionPermissionSetThe process by which a specified permission set is provisioned to the specified target.NN
PutApplicationAccessScopeAdds or updates the list of authorized targets for an IAM Identity Center access scope for an application.NN
PutApplicationAssignmentConfigurationConfigure how users gain access to an application.NN
PutApplicationAuthenticationMethodAdds or updates an authentication method for an application.NN
PutApplicationGrantCreates a configuration for an application to use grants.NN
PutApplicationSessionConfigurationUpdates the session configuration for an application in IAM Identity Center.NN
PutInlinePolicyToPermissionSetAttaches an inline policy to a permission set.NN
PutPermissionsBoundaryToPermissionSetAttaches an Amazon Web Services managed or customer managed policy to the specified PermissionSet as a permissions boundary.NN
RemoveRegionRemoves an additional Region from an IAM Identity Center instance.YN
TagResourceAssociates a set of tags with a specified resource.NN
UntagResourceDisassociates a set of tags from a specified resource.YN
UpdateApplicationUpdates application properties.YN
UpdateInstanceUpdate the details for the instance of IAM Identity Center that is owned by the Amazon Web Services account.YN
UpdateInstanceAccessControlAttributeConfigurationUpdates the IAM Identity Center identity store attributes that you can use with the IAM Identity Center instance for attributes-based access control (ABAC).YN
UpdatePermissionSetUpdates an existing permission set.YN
UpdateTrustedTokenIssuerUpdates the name of the trusted token issuer, or the path of a source attribute or destination attribute for a trusted token issuer configuration.YN
AuthenticateAuthenticate recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NY
CreateTokenCreateToken recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NY
DescribeRegisteredRegionsDescribeRegisteredRegions recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
FederateFederate recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
GetRoleCredentialsGetRoleCredentials recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
GetSsoConfigurationGetSsoConfiguration recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
GetSSOStatusGetSSOStatus recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListAccountRolesListAccountRoles recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListDirectoryAssociationsListDirectoryAssociations recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListProfilesForApplicationListProfilesForApplication recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
LogoutLogout recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN

any: AWS IAM Identity Center (catch-all)

#
Service
sso

Description

Catch-all entry for AWS IAM Identity Center rules that match the service but not a specific eventName.

AssociateDirectory

#
Service
sso

Description

Associates a directory with an IAM Identity Center instance to use it as the identity source.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

DisassociateDirectory

#
Service
sso

Description

Disassociates a directory from an IAM Identity Center instance, removing it as the identity source.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

AddRegion

#
Service
sso

Description

Adds a Region to an IAM Identity Center instance.

AttachCustomerManagedPolicyReferenceToPermissionSet

#
Service
sso

Description

Attaches the specified customer managed policy to the specified PermissionSet.

AttachManagedPolicyToPermissionSet

#
Service
sso

Description

Attaches an Amazon Web Services managed policy ARN to a permission set.

CloudTrail management event, logged by default.

CreateAccountAssignment

#
Service
sso

Description

Assigns access to a principal for a specified Amazon Web Services account using a specified permission set.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "eventVersion": "1.09",
  "userIdentity": {
    "type": "AssumedRole",
    "principalId": "AROA****************:User",
    "arn": "arn:aws:sts::123456789012:assumed-role/AWSReservedSSO_AdministratorAccess_2276cacebc31d3eb/AdanAlvarez",
    "accountId": "123456789012",
    "accessKeyId": "AKIA****************",
    "sessionContext": {
      "sessionIssuer": {
        "type": "Role",
        "principalId": "AROA****************:User",
        "arn": "arn:aws:iam::123456789012:role/aws-reserved/sso.amazonaws.com/euiso-south-2r/AWSReservedSSO_AdministratorAccess_2276cacebc31d3eb",
        "accountId": "123456789012",
        "userName": "AWSReservedSSO_AdministratorAccess_2276cacebc31d3eb"
      },
      "attributes": {
        "creationDate": "2025-05-24T14:45:18Z",
        "mfaAuthenticated": "false"
      }
    }
  },
  "eventTime": "2025-05-24T14:52:07Z",
  "eventSource": "sso.amazonaws.com",
  "eventName": "CreateAccountAssignment",
  "awsRegion": "euiso-south-2r",
  "sourceIPAddress": "0.0.0.0",
  "userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/0.0.0.0 Safari/537.36",
  "requestParameters": {
    "instanceArn": "arn:aws:sso:::instance/ssoins-66846d02039d7f57",
    "targetId": "760507577735",
    "targetType": "AWS_ACCOUNT",
    "permissionSetArn": "arn:aws:sso:::permissionSet/ssoins-66846d02039d7f57/ps-cc3ba8d6d6642c51",
    "principalType": "GROUP",
    "principalId": "AROA****************:User"
  },
  "responseElements": {
    "accountAssignmentCreationStatus": {
      "status": "IN_PROGRESS",
      "requestId": "9987b8b8-20f7-4a42-85a9-17c48c76a74b",
      "targetId": "760507577735",
      "targetType": "AWS_ACCOUNT",
      "permissionSetArn": "arn:aws:sso:::permissionSet/ssoins-66846d02039d7f57/ps-cc3ba8d6d6642c51",
      "principalType": "GROUP",
      "principalId": "AROA****************:User"
    }
  },
  "requestID": "9987b8b8-20f7-4a42-85a9-17c48c76a74b",
  "eventID": "7a0067f3-5a91-4116-ab94-e497b06054ae",
  "readOnly": false,
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.euiso-south-2r.amazonaws.com"
  },
  "sessionCredentialFromConsole": "true"
}

References #

CreateApplication

#
Service
sso

Description

Creates an OAuth 2.0 customer managed application in IAM Identity Center for the given application provider.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "ValidationException",
  "errorMessage": "The application provider with arn 'arn:aws:sso::aws:applicationProvider/app-541391d7d89edb80' is not supported for this action.",
  "eventCategory": "Management",
  "eventID": "6f3a4c0b-db06-4b1d-ad58-45a8b63e32a3",
  "eventName": "CreateApplication",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T21:50:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "fc1843c8-b450-448c-ac26-6e1dcfd27f3d",
  "requestParameters": null,
  "resources": [
    {
      "ARN": "arn:aws:sso:::instance/ssoins-722375f143f78333",
      "accountId": "123456789012",
      "type": "AWS::SSO::Instance"
    },
    {
      "ARN": "arn:aws:sso::aws:applicationProvider/catalog/Statuspage",
      "accountId": "123456789012",
      "type": "AWS::SSO::ApplicationProvider"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateApplicationAssignment

#
Service
sso

Description

Grant application access to a user or group.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "1dcf2125-f12c-35fb-9875-d84df13ff788",
  "eventSource": "sso.amazonaws.com",
  "eventName": "CreateApplicationAssignment",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "1b814a1c-6a6e-4d12-ac4b-f486c6d1c685",
  "userAgent": "q.amazonaws.com",
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::SSO::Instance",
      "ARN": "arn:aws:sso:::EXAMPLE"
    },
    {
      "accountId": "123456789012",
      "type": "AWS::SSO::Application",
      "ARN": "arn:aws:sso::123456789012:application/EXAMPLE"
    }
  ]
}

CreateInstance

#
Service
sso

Description

Creates an instance of IAM Identity Center for a standalone Amazon Web Services account that is not managed by Organizations or a member Amazon Web Services account in an organization.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationConfigurationDefaults": {
      "allowedMfaTypes": [
        "TOTP",
        "WEBAUTHN"
      ],
      "mfaMode": "CONTEXT_AWARE",
      "noMfaSignInBehavior": "ALLOWED_WITH_ENROLLMENT",
      "noPasswordSignInBehavior": "BLOCKED"
    },
    "SessionConfigurationDefaults": {
      "extendedSessionEnabledAppProviders": [
        "codewhisperer"
      ],
      "sessionDuration": "PT8H"
    }
  },
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "d14606dd-36a2-48e7-a20c-f8cc8aeb6ad4",
  "eventName": "CreateInstance",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T21:50:08Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "1e2db816-ec40-4ae3-be88-871f719f38f9",
  "requestParameters": {
    "clientToken": "7777c2d8-02a9-46e7-b8de-2eea7d616c45",
    "name": "dwfix-sso-sample",
    "tags": [
      {
        "key": "dw-teardown",
        "value": "true"
      }
    ]
  },
  "responseElements": {
    "instanceArn": "arn:aws:sso:::instance/ssoins-722375f143f78333"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateInstanceAccessControlAttributeConfiguration

#
Service
sso

Description

Enables the attributes-based access control (ABAC) feature for the specified IAM Identity Center instance.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "ValidationException",
  "errorMessage": "This operation is not supported for account instances of IAM Identity Center.",
  "eventCategory": "Management",
  "eventID": "0a0ee9b5-92b5-49c5-86b4-42b1f21c7dfd",
  "eventName": "CreateInstanceAccessControlAttributeConfiguration",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T21:50:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7a9d9019-5a18-4462-875f-6c5941e69576",
  "requestParameters": null,
  "resources": [
    {
      "ARN": "arn:aws:sso:::instance/ssoins-722375f143f78333",
      "accountId": "123456789012",
      "type": "AWS::SSO::Instance"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreatePermissionSet

#
Service
sso

Description

Creates a permission set within a specified IAM Identity Center instance.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "ValidationException",
  "errorMessage": "This operation is not supported for account instances of IAM Identity Center.",
  "eventCategory": "Management",
  "eventID": "f36f91e7-9d93-48b8-8c38-5742b2a4e66d",
  "eventName": "CreatePermissionSet",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T21:50:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2f04300f-4307-4c91-9df9-5bb607c86e6f",
  "requestParameters": null,
  "resources": [
    {
      "ARN": "arn:aws:sso:::instance/ssoins-722375f143f78333",
      "accountId": "123456789012",
      "type": "AWS::SSO::Instance"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateTrustedTokenIssuer

#
Service
sso

Description

Creates a connection to a trusted token issuer in an instance of IAM Identity Center.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'trustedTokenIssuerConfiguration.oidcJwtConfiguration.identityStoreAttributePath' failed to satisfy constraint: Member must satisfy regular expression pattern: \\p{L}+(?:\\.\\p{L}+){0,2}",
  "eventCategory": "Management",
  "eventID": "d3d97d48-cacb-4c1b-aa9c-0dfe0c532816",
  "eventName": "CreateTrustedTokenIssuer",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T21:50:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "465369ad-aee4-4c9f-89a1-973385476e9c",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteAccountAssignment

#
Service
sso

Description

Deletes a principal's access from a specified Amazon Web Services account using a specified permission set.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'targetId' failed to satisfy constraint: Member must satisfy regular expression pattern: \\d{12}; Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'principalId' failed to satisfy constraint: Member must satisfy regular expression pattern: ([0-9a-f]{10}-|)[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "0a7da0f8-2a06-4a0f-9979-f9f86636a9e4",
  "eventName": "DeleteAccountAssignment",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T19:26:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7d80020c-2435-48d2-88ae-3d64ce5ba4c4",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteApplication

#
Service
sso

Description

Deletes the association with the application.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
  "eventCategory": "Management",
  "eventID": "935860dc-e670-4032-a274-9cd9f3d104a6",
  "eventName": "DeleteApplication",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T19:26:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0153f046-45a2-48e8-8168-9e52c1e14ce4",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteApplicationAccessScope

#
Service
sso

Description

Deletes an IAM Identity Center access scope from an application.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'scope' failed to satisfy constraint: Member must satisfy regular expression pattern: ([A-Za-z0-9_]{1,50})(:[A-Za-z0-9_]{1,50}){0,1}(:[A-Za-z0-9_]{1,50}){0,1}; Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
  "eventCategory": "Management",
  "eventID": "b8228359-b44d-47cf-a91a-1f601b33c3d3",
  "eventName": "DeleteApplicationAccessScope",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T19:26:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "31ff0dc3-c70f-41d3-881b-8049db9a9b12",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteApplicationAssignment

#
Service
sso

Description

Revoke application access to an application by deleting application assignments for a user or group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}; Value of input 'principalId' failed to satisfy constraint: Member must satisfy regular expression pattern: ([0-9a-f]{10}-|)[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}",
  "eventCategory": "Management",
  "eventID": "b61fc3d5-ce0b-4c55-ad7d-af3907715778",
  "eventName": "DeleteApplicationAssignment",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T19:26:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "fb4254ed-67c7-45ba-9fcf-ae8f2307a568",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteApplicationAuthenticationMethod

#
Service
sso

Description

Deletes an authentication method from an application.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
  "eventCategory": "Management",
  "eventID": "0464b722-4f76-4a59-96fb-3a5a70b8c8f4",
  "eventName": "DeleteApplicationAuthenticationMethod",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T19:26:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ba4bc3de-277f-4750-83cf-841603d7d134",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteApplicationGrant

#
Service
sso

Description

Deletes a grant from an application.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
  "eventCategory": "Management",
  "eventID": "dbb7fceb-c8fc-40f4-b522-ed0aa42cff32",
  "eventName": "DeleteApplicationGrant",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T19:26:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f712fdb2-790d-445b-9efe-b1dafbc2c358",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteInlinePolicyFromPermissionSet

#
Service
sso

Description

Deletes the inline policy from a specified permission set.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "78bda4de-ba5d-4710-bdb8-d5fcc19c3fd9",
  "eventName": "DeleteInlinePolicyFromPermissionSet",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T19:26:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "fdf23a28-2200-4fb7-94f8-a081629a70b8",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteInstance

#
Service
sso

Description

Deletes the instance of IAM Identity Center.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "fdd5b72c-926c-4540-b9f4-216b5b4a3d4d",
  "eventName": "DeleteInstance",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T19:26:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2cd4caee-626c-4cb3-8880-56374d8ab208",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteInstanceAccessControlAttributeConfiguration

#
Service
sso

Description

Disables the attributes-based access control (ABAC) feature for the specified IAM Identity Center instance and deletes all of the attribute mappings that have been configured.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "2a69f3b2-418c-48c5-bf2c-5b8b0e2eb280",
  "eventName": "DeleteInstanceAccessControlAttributeConfiguration",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T19:26:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "33ffd94f-4634-4d6d-a91c-f555868c502c",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeletePermissionsBoundaryFromPermissionSet

#
Service
sso

Description

Deletes the permissions boundary from a specified PermissionSet.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "12eff39e-8b0d-4b90-aa3b-30a1d6a9ea06",
  "eventName": "DeletePermissionsBoundaryFromPermissionSet",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T19:26:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "27223b81-3510-445a-bca0-fa9e0a84ba5b",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeletePermissionSet

#
Service
sso

Description

Deletes the specified permission set.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "4d191cd1-f1a1-4566-9035-0eff31adddd2",
  "eventName": "DeletePermissionSet",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T19:26:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6ac5048d-5ded-486d-bd36-62262615ea01",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTrustedTokenIssuer

#
Service
sso

Description

Deletes a trusted token issuer configuration from an instance of IAM Identity Center.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'trustedTokenIssuerArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:trustedTokenIssuer/(sso)?ins-[a-zA-Z0-9-.]{16}/tti-[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}",
  "eventCategory": "Management",
  "eventID": "147822d3-ec5d-4097-8ea0-22d59ec269a2",
  "eventName": "DeleteTrustedTokenIssuer",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T19:26:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "86471af4-098e-4abc-93d6-fd1c17f6cb88",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeAccountAssignmentCreationStatus

#
Service
sso

Description

Describes the status of the assignment creation request.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'accountAssignmentCreationRequestId' failed to satisfy constraint: Member must satisfy regular expression pattern: \\b[0-9a-f]{8}\\b-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-\\b[0-9a-f]{12}\\b; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "016a0e24-a9a8-4005-a658-b48c5807f3d4",
  "eventName": "DescribeAccountAssignmentCreationStatus",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "b25378a1-899b-4fe0-813c-88d00bb668f8",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeAccountAssignmentDeletionStatus

#
Service
sso

Description

Describes the status of the assignment deletion request.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'accountAssignmentDeletionRequestId' failed to satisfy constraint: Member must satisfy regular expression pattern: \\b[0-9a-f]{8}\\b-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-\\b[0-9a-f]{12}\\b; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "c3bb1987-366e-4f26-86b7-10d4012648b6",
  "eventName": "DescribeAccountAssignmentDeletionStatus",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "edea5050-fcb1-4695-a9e6-430d9e029cd4",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeApplication

#
Service
sso

Description

Retrieves the details of an application associated with an instance of IAM Identity Center.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
  "eventCategory": "Management",
  "eventID": "86183a1f-fa11-401b-860e-0e7aebcf50a9",
  "eventName": "DescribeApplication",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "14a612f7-d480-45fc-88b0-d37f7a275657",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeApplicationAssignment

#
Service
sso

Description

Retrieves a direct assignment of a user or group to an application.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}; Value of input 'principalId' failed to satisfy constraint: Member must satisfy regular expression pattern: ([0-9a-f]{10}-|)[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}",
  "eventCategory": "Management",
  "eventID": "e4d56aa8-3fc0-4239-8b27-f6c057b632e5",
  "eventName": "DescribeApplicationAssignment",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "92c87916-a09d-4afc-8eca-81ff8ac779cd",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeApplicationProvider

#
Service
sso

Description

Retrieves details about a provider that can be used to connect an Amazon Web Services managed application or customer managed application to IAM Identity Center.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'applicationProviderArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::aws:applicationProvider/[a-zA-Z0-9-/]+",
  "eventCategory": "Management",
  "eventID": "b0bcc21b-746d-4466-9fb2-d34d89af4ae5",
  "eventName": "DescribeApplicationProvider",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "19e377dc-6187-4a07-a52e-ecd0d3fe9b66",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeInstance

#
Service
sso

Description

Returns the details of an instance of IAM Identity Center.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "9e5b0d7d-4d17-4e7a-b900-a3d88030eeac",
  "eventName": "DescribeInstance",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "87e9bed0-ced1-41ef-9f67-a82be107a8e0",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeInstanceAccessControlAttributeConfiguration

#
Service
sso

Description

Returns the list of IAM Identity Center identity store attributes that have been configured to work with attributes-based access control (ABAC) for the specified IAM Identity Center instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "b16ac8a8-7dcf-41fc-ad36-1c848cac5ff0",
  "eventName": "DescribeInstanceAccessControlAttributeConfiguration",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "c2ff0ed5-3d46-4451-8989-79e16667ce04",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribePermissionSet

#
Service
sso

Description

Gets the details of the permission set.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "d12de061-9982-4673-95f1-9b76a21519c9",
  "eventName": "DescribePermissionSet",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "989cd211-a9ef-449a-a38c-2e2ca2ba26d7",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribePermissionSetProvisioningStatus

#
Service
sso

Description

Describes the status for the given permission set provisioning request.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'provisionPermissionSetRequestId' failed to satisfy constraint: Member must satisfy regular expression pattern: \\b[0-9a-f]{8}\\b-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-\\b[0-9a-f]{12}\\b; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "3f84a35f-aead-4b43-8efb-2fdce9fdd110",
  "eventName": "DescribePermissionSetProvisioningStatus",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "81536275-fe77-433e-b925-2b7e34aaf1e9",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeRegion

#
Service
sso

Description

Retrieves details about a specific Region enabled in an IAM Identity Center instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'regionName' failed to satisfy constraint: Member must satisfy regular expression pattern: ([a-z]+-){2,3}\\d; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "1128d804-f0dd-4fb7-ab77-eeb600f7b3b1",
  "eventName": "DescribeRegion",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "c2b97f0c-2bc1-42ad-bfe9-c9ba09e34787",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeTrustedTokenIssuer

#
Service
sso

Description

Retrieves details about a trusted token issuer configuration stored in an instance of IAM Identity Center.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'trustedTokenIssuerArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:trustedTokenIssuer/(sso)?ins-[a-zA-Z0-9-.]{16}/tti-[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}",
  "eventCategory": "Management",
  "eventID": "679d0417-850e-4a94-8cf9-75ae7e313369",
  "eventName": "DescribeTrustedTokenIssuer",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "f900bd52-0501-46b6-ad28-255dad30c69e",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DetachCustomerManagedPolicyReferenceFromPermissionSet

#
Service
sso

Description

Detaches the specified customer managed policy from the specified PermissionSet.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "d4fcb2e3-bf98-4d5b-96a0-03ad4c973b8a",
  "eventName": "DetachCustomerManagedPolicyReferenceFromPermissionSet",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T19:26:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8e82f77f-c58c-42d0-9924-dc595a529de7",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DetachManagedPolicyFromPermissionSet

#
Service
sso

Description

Detaches the attached Amazon Web Services managed policy ARN from the specified permission set.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}; Value of input 'managedPolicyArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:iam::aws:policy((/[A-Za-z0-9\\.,\\+@=_-]+)*)/([A-Za-z0-9\\.,\\+=@_-]+)",
  "eventCategory": "Management",
  "eventID": "29434892-0b1c-4f6a-8dde-48b16e05edae",
  "eventName": "DetachManagedPolicyFromPermissionSet",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T19:26:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c178747a-5ab2-40e5-876d-62aa4357d5c8",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetApplicationAccessScope

#
Service
sso

Description

Retrieves the authorized targets for an IAM Identity Center access scope for an application.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'scope' failed to satisfy constraint: Member must satisfy regular expression pattern: ([A-Za-z0-9_]{1,50})(:[A-Za-z0-9_]{1,50}){0,1}(:[A-Za-z0-9_]{1,50}){0,1}; Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
  "eventCategory": "Management",
  "eventID": "68e2d2db-537b-4894-b661-bd47e1a3ac43",
  "eventName": "GetApplicationAccessScope",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "9c4618a7-f321-4024-b8ca-3d236c361e89",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetApplicationAssignmentConfiguration

#
Service
sso

Description

Retrieves the configuration of PutApplicationAssignmentConfiguration.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
  "eventCategory": "Management",
  "eventID": "a6234748-ac0b-446b-ae05-4fe2f4dc028d",
  "eventName": "GetApplicationAssignmentConfiguration",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "2c0ae60a-f2f2-4298-94d1-d91568a0659d",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetApplicationAuthenticationMethod

#
Service
sso

Description

Retrieves details about an authentication method used by an application.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
  "eventCategory": "Management",
  "eventID": "79a94fce-7af0-4dcd-8e39-92748c0f63a4",
  "eventName": "GetApplicationAuthenticationMethod",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "47f7356c-3f8e-47a8-ba3b-4e221fa571dc",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetApplicationGrant

#
Service
sso

Description

Retrieves details about an application grant.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
  "eventCategory": "Management",
  "eventID": "35ac0d0b-3a57-4e87-9402-47484a102ee3",
  "eventName": "GetApplicationGrant",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "6f812506-759e-4f9c-987b-3b077ac2f1fa",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetApplicationSessionConfiguration

#
Service
sso

Description

Retrieves the session configuration for an application in IAM Identity Center.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
  "eventCategory": "Management",
  "eventID": "431258c9-c2b8-40d6-8c47-ff7a304da706",
  "eventName": "GetApplicationSessionConfiguration",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "287aeda6-1c66-4960-bfb4-fd9c04c3e1a6",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetInlinePolicyForPermissionSet

#
Service
sso

Description

Obtains the inline policy assigned to the permission set.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "be503feb-4869-4132-8568-c42b207f1ac6",
  "eventName": "GetInlinePolicyForPermissionSet",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "b84365a3-ee8f-43f8-8454-804a9c0adaa5",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetPermissionsBoundaryForPermissionSet

#
Service
sso

Description

Obtains the permissions boundary for a specified PermissionSet.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "97a3a36c-1ed9-4ff4-b83e-27cb048632c2",
  "eventName": "GetPermissionsBoundaryForPermissionSet",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "c4036cdd-1528-425f-9e29-fe5bad909f4d",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListAccountAssignmentCreationStatus

#
Service
sso

Description

Lists the status of the Amazon Web Services account assignment creation requests for a specified IAM Identity Center instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "afa72cf8-4507-4cf6-924a-f58d1fa44f0d",
  "eventName": "ListAccountAssignmentCreationStatus",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "bfa290c5-6617-42b9-af62-fdb92517ab2e",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListAccountAssignmentDeletionStatus

#
Service
sso

Description

Lists the status of the Amazon Web Services account assignment deletion requests for a specified IAM Identity Center instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "e4c4aa51-2b6d-4267-abd7-0b856b6763b2",
  "eventName": "ListAccountAssignmentDeletionStatus",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "344a58d1-7856-4a5a-8fb8-5267148ac09e",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListAccountAssignments

#
Service
sso

Description

Lists the assignee of the specified Amazon Web Services account with the specified permission set.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'accountId' failed to satisfy constraint: Member must satisfy regular expression pattern: \\d{12}; Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "e013cad4-04b2-4c60-ac4e-be19b6131bbc",
  "eventName": "ListAccountAssignments",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "64475bef-0eb2-4d33-b1ad-12aa9af52adb",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListAccountAssignmentsForPrincipal

#
Service
sso

Description

Retrieves a list of the IAM Identity Center associated Amazon Web Services accounts that the principal has access to.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'principalId' failed to satisfy constraint: Member must satisfy regular expression pattern: ([0-9a-f]{10}-|)[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "76952ead-da8a-4f3a-8e69-f156121d167f",
  "eventName": "ListAccountAssignmentsForPrincipal",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "f613e680-c412-4355-adac-4af4b55b5ebd",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListAccountsForProvisionedPermissionSet

#
Service
sso

Description

Lists all the Amazon Web Services accounts where the specified permission set is provisioned.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "a0b8844d-2293-402e-937c-2337376bb695",
  "eventName": "ListAccountsForProvisionedPermissionSet",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "1720e63f-d35c-4bf9-a231-e78431daaafb",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListApplicationAccessScopes

#
Service
sso

Description

Lists the access scopes and authorized targets associated with an application.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
  "eventCategory": "Management",
  "eventID": "593fa577-55d5-4da4-bd9a-e67cda644a5c",
  "eventName": "ListApplicationAccessScopes",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "3ed69112-e2d9-4d85-bb37-49944e61848d",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListApplicationAssignments

#
Service
sso

Description

Lists Amazon Web Services account users that are assigned to an application.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
  "eventCategory": "Management",
  "eventID": "2fdfc090-de4f-4929-a6a4-cfb4ad2a64f3",
  "eventName": "ListApplicationAssignments",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "ac4d0754-cfc5-4e5f-8c2d-f49a188ae6f5",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListApplicationAssignmentsForPrincipal

#
Service
sso

Description

Lists the applications to which a specified principal is assigned.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'principalId' failed to satisfy constraint: Member must satisfy regular expression pattern: ([0-9a-f]{10}-|)[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "3a931b5d-5f8e-413b-89fb-f3b08be9407a",
  "eventName": "ListApplicationAssignmentsForPrincipal",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "bda809bd-8f89-47ce-a3c9-f35ae2d02088",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListApplicationAuthenticationMethods

#
Service
sso

Description

Lists all of the authentication methods supported by the specified application.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
  "eventCategory": "Management",
  "eventID": "ae7512a9-b79b-4b3d-9e10-e46dd553b05c",
  "eventName": "ListApplicationAuthenticationMethods",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "a2bf940e-3124-48e4-8f65-f33fce3b165f",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListApplicationGrants

#
Service
sso

Description

List the grants associated with an application.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
  "eventCategory": "Management",
  "eventID": "6115e575-2fc9-462b-bb44-330609f292fb",
  "eventName": "ListApplicationGrants",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "c2e9aa12-c858-448f-8bc6-5378ad51a180",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListApplicationProviders

#
Service
sso

Description

Lists the application providers configured in the IAM Identity Center identity store.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "eb4ea434-6e93-497f-961f-afe0cff48a8d",
  "eventName": "ListApplicationProviders",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:32:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "0f8ceaad-3cb9-427e-998d-47e709008141",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListApplications

#
Service
sso

Description

Lists all applications associated with the instance of IAM Identity Center.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "7aa5c00b-fe53-4eba-8490-59c4ebd53890",
  "eventName": "ListApplications",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "8be5cbd8-fbe0-4c4f-a4c1-9c9b3ad9c5e1",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ListCustomerManagedPolicyReferencesInPermissionSet

#
Service
sso

Description

Lists all customer managed policies attached to a specified PermissionSet.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "7b3c914d-e12f-4b5b-924c-6f0f95bbf7b4",
  "eventName": "ListCustomerManagedPolicyReferencesInPermissionSet",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "c169413d-45c2-4044-9cc5-2cd64721a94f",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListInstances

#
Service
sso

Description

Lists the details of the organization and account instances of IAM Identity Center that were created in or visible to the account calling this API.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "3a3c99ad-4495-4ab2-a5a5-b3058c8c7587",
  "eventName": "ListInstances",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:32:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "3f1879fa-deb2-4739-9f10-bafbb1071bdb",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListManagedPoliciesInPermissionSet

#
Service
sso

Description

Lists the Amazon Web Services managed policy that is attached to a specified permission set.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "9178b202-7d57-479f-8744-d3a473bb04a0",
  "eventName": "ListManagedPoliciesInPermissionSet",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "0e8e3c5d-dcb4-4185-8749-7f550ef45679",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListPermissionSetProvisioningStatus

#
Service
sso

Description

Lists the status of the permission set provisioning requests for a specified IAM Identity Center instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "a99c254d-393d-4613-be22-fb0b66e50411",
  "eventName": "ListPermissionSetProvisioningStatus",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "8f4f3ad7-74ed-4644-88e3-73e0a7952c14",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListPermissionSets

#
Service
sso

Description

Lists the PermissionSets in an IAM Identity Center instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "92b7a8dd-61ce-4fb8-a36f-62ac10835bf9",
  "eventName": "ListPermissionSets",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "afd690a7-0227-418a-8d0d-2e4022d5f149",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListPermissionSetsProvisionedToAccount

#
Service
sso

Description

Lists all the permission sets that are provisioned to a specified Amazon Web Services account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'accountId' failed to satisfy constraint: Member must satisfy regular expression pattern: \\d{12}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "428e40aa-917a-4c9e-8a85-979cf9a74024",
  "eventName": "ListPermissionSetsProvisionedToAccount",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "531a8b55-d443-4155-9667-bbe8d2480aa9",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListRegions

#
Service
sso

Description

Lists all enabled Regions of an IAM Identity Center instance, including those that are being added or removed.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "600b7a8a-0319-4d29-9c7e-5eff0077bc0d",
  "eventName": "ListRegions",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "64db2b0b-8c68-43c8-b137-7cb0f6d3d71e",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListTagsForResource

#
Service
sso

Description

Lists the tags that are attached to a specified resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'resourceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::((:instance/(sso)?ins-[a-zA-Z0-9-.]{16})|(:permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16})|(\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16})|(\\d{12}:trustedTokenIssuer/(sso)?ins-[a-zA-Z0-9-.]{16}/tti-[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}))",
  "eventCategory": "Management",
  "eventID": "77bf3fad-3e2f-4f66-9f27-fddaf78d14bd",
  "eventName": "ListTagsForResource",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "aaef9161-74ef-4549-8bdd-c82f19ce0d22",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListTrustedTokenIssuers

#
Service
sso

Description

Lists all the trusted token issuers configured in an instance of IAM Identity Center.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "3488ce2a-d21d-4095-8a08-a9fddc3f3a82",
  "eventName": "ListTrustedTokenIssuers",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T18:46:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "ad0664de-e0a7-427c-8ae9-da0177685722",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ProvisionPermissionSet

#
Service
sso

Description

The process by which a specified permission set is provisioned to the specified target.

PutApplicationAccessScope

#
Service
sso

Description

Adds or updates the list of authorized targets for an IAM Identity Center access scope for an application.

PutApplicationAssignmentConfiguration

#
Service
sso

Description

Configure how users gain access to an application.

PutApplicationAuthenticationMethod

#
Service
sso

Description

Adds or updates an authentication method for an application.

PutApplicationGrant

#
Service
sso

Description

Creates a configuration for an application to use grants.

PutApplicationSessionConfiguration

#
Service
sso

Description

Updates the session configuration for an application in IAM Identity Center.

PutInlinePolicyToPermissionSet

#
Service
sso

Description

Attaches an inline policy to a permission set.

CloudTrail management event, logged by default.

PutPermissionsBoundaryToPermissionSet

#
Service
sso

Description

Attaches an Amazon Web Services managed or customer managed policy to the specified PermissionSet as a permissions boundary.

RemoveRegion

#
Service
sso

Description

Removes an additional Region from an IAM Identity Center instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'regionName' failed to satisfy constraint: Member must satisfy regular expression pattern: ([a-z]+-){2,3}\\d; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "ee8316ec-4288-4ace-af4b-9c656a97ff53",
  "eventName": "RemoveRegion",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T19:26:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "cb21abc1-b978-49ab-b571-79f8931b455b",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

TagResource

#
Service
sso

Description

Associates a set of tags with a specified resource.

UntagResource

#
Service
sso

Description

Disassociates a set of tags from a specified resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'resourceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::((:instance/(sso)?ins-[a-zA-Z0-9-.]{16})|(:permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16})|(\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16})|(\\d{12}:trustedTokenIssuer/(sso)?ins-[a-zA-Z0-9-.]{16}/tti-[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}))",
  "eventCategory": "Management",
  "eventID": "c5bcd3f8-4f04-4cf2-bf8d-2a8073809cae",
  "eventName": "UntagResource",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T19:26:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6e08ccb1-eb69-4a0b-b6a4-c5e531ccad45",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateApplication

#
Service
sso

Description

Updates application properties.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'applicationArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:application/(sso)?ins-[a-zA-Z0-9-.]{16}/apl-[a-zA-Z0-9]{16}",
  "eventCategory": "Management",
  "eventID": "88ab7396-fa5a-426c-bdf1-ec1b2437a9e4",
  "eventName": "UpdateApplication",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T19:26:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "4ed52d46-0df7-4b0e-b21e-f916a7d9d31e",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateInstance

#
Service
sso

Description

Update the details for the instance of IAM Identity Center that is owned by the Amazon Web Services account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "7e2190cc-5ee5-4bd4-a169-29521bf481a0",
  "eventName": "UpdateInstance",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T19:26:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "757e1bf6-f8cb-47c8-8356-6478e6d8e339",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateInstanceAccessControlAttributeConfiguration

#
Service
sso

Description

Updates the IAM Identity Center identity store attributes that you can use with the IAM Identity Center instance for attributes-based access control (ABAC).

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "8e9bbaca-f291-4ba8-a8e7-5723ddea241a",
  "eventName": "UpdateInstanceAccessControlAttributeConfiguration",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T19:26:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "19ae9415-6a28-4e92-a63d-8fd234a7b18f",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdatePermissionSet

#
Service
sso

Description

Updates an existing permission set.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'permissionSetArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}; Value of input 'instanceArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}",
  "eventCategory": "Management",
  "eventID": "eef905d5-df70-4abd-8d3f-30234dc0d71f",
  "eventName": "UpdatePermissionSet",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T19:26:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0f3f1d86-6d12-45b3-b33a-f09bba9a4318",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateTrustedTokenIssuer

#
Service
sso

Description

Updates the name of the trusted token issuer, or the path of a source attribute or destination attribute for a trusted token issuer configuration.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Value of input 'trustedTokenIssuerArn' failed to satisfy constraint: Member must satisfy regular expression pattern: arn:aws(-[a-z]{1,5}){0,3}:sso::\\d{12}:trustedTokenIssuer/(sso)?ins-[a-zA-Z0-9-.]{16}/tti-[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}",
  "eventCategory": "Management",
  "eventID": "77a7f467-e857-48be-996d-74a309432ff6",
  "eventName": "UpdateTrustedTokenIssuer",
  "eventSource": "sso.amazonaws.com",
  "eventTime": "2026-06-29T19:26:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "61f8af88-b540-4ad0-8611-24a9ce50879b",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Authenticate

#
Service
sso

Description

Authenticate recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "d21742b0-b345-4429-9994-5a91ff17bb0f",
  "eventSource": "sso.amazonaws.com",
  "eventName": "Authenticate",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "fd2fc447-34b5-48c9-a22b-ffea5fe653a1",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:153.0) Gecko/20100101 Firefox/153.0"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

CreateToken

#
Service
sso

Description

CreateToken recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "f615ca98-490c-4e38-9a8d-9db0379b38ed",
  "eventSource": "sso.amazonaws.com",
  "eventName": "CreateToken",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "87342727-4500-4289-85d0-f5778b1b83c0",
  "userAgent": "aws-cli/2.35.1 md/awscrt#0.32.2 ua/2.1 os/windows#11 md/arch#amd64 lang/python#3.14.5 md/pyimpl#CPython m/Z,E,b cfg/retry-mode#standard md/installer#exe sid/c8a437b6b651 md/prompt#off md/command#sso.login md/sso#auth",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "type": "IdentityStoreId",
      "ARN": "d-906750297c"
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

DescribeRegisteredRegions

#
Service
sso

Description

DescribeRegisteredRegions recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "f250a648-e0b1-4c9b-95c0-4123c60b7a86",
  "eventSource": "sso.amazonaws.com",
  "eventName": "DescribeRegisteredRegions",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "cd8c8282-8206-4693-b965-6983a8734d96",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:153.0) Gecko/20100101 Firefox/153.0",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-east-1.amazonaws.com"
  }
}

Federate

#
Service
sso

Description

Federate recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "92fad055-e58b-4209-935d-4b65abc148c0",
  "eventSource": "sso.amazonaws.com",
  "eventName": "Federate",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "061a1ab4-3ef9-4e9e-b07c-d53a1c62b395",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
}

GetRoleCredentials

#
Service
sso

Description

GetRoleCredentials recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "ff333688-6213-41d9-9663-2282b22efe06",
  "eventSource": "sso.amazonaws.com",
  "eventName": "GetRoleCredentials",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "1935edb1-5624-4a3c-baea-ee8c74f3b75d",
  "userAgent": "Boto3/1.43.15 md/Botocore#1.43.15 ua/2.1 os/macos#25.5.0 md/arch#arm64 lang/python#3.14.6 md/pyimpl#CPython m/Z,r,D,b cfg/retry-mode#legacy Botocore/1.43.15"
}

GetSsoConfiguration

#
Service
sso

Description

GetSsoConfiguration recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "491245de-1ac1-37d6-8a03-bccc9f7e3423",
  "eventSource": "sso.amazonaws.com",
  "eventName": "GetSsoConfiguration",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "3dcd4bd6-344c-4026-84ef-3954c693f94c",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-east-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::SSO::Instance",
      "ARN": "arn:aws:sso:::EXAMPLE"
    }
  ]
}

GetSSOStatus

#
Service
sso

Description

GetSSOStatus recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "9964b13f-ca3a-4434-84b9-6523739de1f3",
  "eventSource": "sso.amazonaws.com",
  "eventName": "GetSSOStatus",
  "awsRegion": "us-east-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "40a89441-1a23-42e0-84e9-bb4ef824d482",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-east-2.amazonaws.com"
  }
}

ListAccountRoles

#
Service
sso

Description

ListAccountRoles recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "7e72f287-205c-42ea-934f-349bb6ba7914",
  "eventSource": "sso.amazonaws.com",
  "eventName": "ListAccountRoles",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "e2c2401f-134f-441e-814b-9f2c560e913f",
  "userAgent": "aws-cli/2.33.8 md/awscrt#0.29.1 ua/2.1 os/macos#24.6.0 md/arch#arm64 lang/python#3.13.11 md/pyimpl#CPython m/Z,C,b,E cfg/retry-mode#standard md/installer#exe sid/8bfe8f74a9f9 md/prompt#off md/command#configure.sso"
}

ListDirectoryAssociations

#
Service
sso

Description

ListDirectoryAssociations recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "d287a4d6-7707-3fbf-b2f5-0c50b5d5e241",
  "eventSource": "sso.amazonaws.com",
  "eventName": "ListDirectoryAssociations",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "95becf14-c4c2-4eb7-bdc2-cdbf95bbf5d0",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "sso.us-east-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::SSO::Instance",
      "ARN": "arn:aws:sso:::EXAMPLE"
    }
  ]
}

ListProfilesForApplication

#
Service
sso

Description

ListProfilesForApplication recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "bf97d7e2-a93f-456c-973f-83760dba3743",
  "eventSource": "sso.amazonaws.com",
  "eventName": "ListProfilesForApplication",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "fcee9ee1-54f5-4894-92d3-9f988c4ce99a",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
}

Logout

#
Service
sso

Description

Logout recorded by CloudTrail for AWS IAM Identity Center. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "08313f16-0013-4951-bf51-61779c174651",
  "eventSource": "sso.amazonaws.com",
  "eventName": "Logout",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "c6de8511-eb36-44eb-8e62-6b50152747c2",
  "userAgent": "aws-cli/2.36.8 md/awscrt#0.36.0 ua/2.1 os/macos#25.5.0 md/arch#arm64 lang/python#3.14.6 md/pyimpl#CPython m/E,r,s,Z,b cfg/retry-mode#standard md/installer#source sid/df423b67c71b md/prompt#off md/command#sso.logout"
}