Before you begin, make sure you have the following:
An AWS account - You can create an AWS account if you do not have one already.
AWS permissions - As a Kiro admin, you must have the permissions to access the Kiro console in AWS in order to subscribe and manage Kiro users. The minimum permissions you'll need are described in Policy: Allow administrators to configure Kiro and subscribe users.
Identity Provider for users/groups - You can either connect to IAM Identity Center, Okta or Microsoft Entra ID, with the identities of the users you want to subscribe to Kiro. It is recommended to use AWS Organizations when setting up AWS IAM Identity Center, as this enables an organization instance that provides centralized identity management across multiple AWS accounts. Note that individual account instances cannot be upgraded to organization instances and would require deletion and recreation.
Users and groups - You can add users and groups from your Identity Provider's built-in directory, or to an external identity provider (IdP) that is connected to IAM Identity Center.
Subscribing your team to Kiro