Amazon SageMaker Unified Studio adds identity and user management features
Simplify user access control and SSO setup while maintaining security across your ML teams with unified administration.
View original announcement →Visual Summary
What's New
Amazon SageMaker Unified Studio has introduced enhanced identity and user management capabilities for both IAM and Identity Center domain types. For IAM domains, administrators can now configure AWS IAM Identity Center to enable SSO onboarding and manage a unified view of all domain users from a single administration page. For Identity Center domains, users can now federate access via IAM roles while maintaining isolated, auditable sessions even when multiple users share the same role.
How It Works
- In SageMaker IAM domains, administrators configure AWS IAM Identity Center integration through the SageMaker Unified Studio admin portal, after which they can add a mix of IAM roles, IAM users, IAM Identity Center users, and IAM Identity Center groups as project members within the same project.
- A new domain user management page consolidates all active domain users into a single screen, allowing administrators to adjust access and permissions without navigating multiple consoles.
- In SageMaker Identity Center domains, federated access via IAM roles is now supported by having SageMaker Unified Studio generate a unique user session per federated principal — meaning that even if two users assume the same IAM role, their sessions are isolated, their work is not overwritten, and their individual actions are independently attributable for audit purposes via AWS CloudTrail or equivalent logging mechanisms.
Why It's Important
- These features address a common enterprise pain point: organizations rarely use a single, uniform authentication method across all teams and users.
- By allowing both IAM-native identities and corporate SSO identities (via IAM Identity Center) to coexist within the same SageMaker Unified Studio project, AWS removes a significant collaboration barrier.
- The per-session isolation for federated IAM role users is particularly important for compliance and security teams, as it enables individual-level auditability even in environments where role sharing is operationally necessary — a requirement in many regulated industries.
How It's Different
- Previously, SageMaker IAM domains and Identity Center domains operated with more rigid identity boundaries: IAM domains lacked native SSO integration, and Identity Center domains did not support IAM role federation.
- Mixing identity types within a single project was not straightforward, forcing organizations to either standardize on one authentication method or manage separate domains.
- The new domain user management page also replaces a fragmented experience where administrators had to cross-reference multiple IAM and Identity Center consoles to get a complete picture of who had access to a domain.
- The per-session uniqueness for shared IAM roles in Identity Center domains is a new capability that did not previously exist, closing a gap where shared-role users could inadvertently overwrite each other's work.
When to Prefer It
- These features are most valuable for enterprise organizations that have heterogeneous identity environments — for example, teams where some members authenticate via corporate SSO (Identity Center) and others use programmatic IAM roles or legacy IAM users.
- Organizations in regulated industries (finance, healthcare, government) that require per-user audit trails but cannot avoid IAM role sharing should specifically leverage the federated session isolation in Identity Center domains.
- Administrators managing large teams will benefit from the consolidated user management page to reduce operational overhead.
- If your organization is already standardized on a single identity method and has no cross-authentication collaboration needs, the impact of these features will be more limited.
Availability
- These features are generally available (GA) as of May 7, 2026.
- They are supported across 15 AWS regions: Asia Pacific (Mumbai, Seoul, Singapore, Sydney, Tokyo), Canada (Central), Europe (Frankfurt, Ireland, London, Paris, Stockholm), South America (São Paulo), US East (N.
- Virginia, Ohio), and US West (Oregon).
- Notable regions not yet listed include AWS GovCloud (US), China regions, and several newer commercial regions, which may be relevant for public sector or data-sovereignty use cases.
- No preview or beta limitations were indicated in the announcement.