Select your cookie preferences

We use essential cookies and similar tools that are necessary to provide our site and services. We use performance cookies to collect anonymous statistics, so we can understand how customers use our site and make improvements. Essential cookies cannot be deactivated, but you can choose “Customize” or “Decline” to decline performance cookies.

If you agree, AWS and approved third parties will also use cookies to provide useful site features, remember your preferences, and display relevant content, including relevant advertising. To accept or decline all non-essential cookies, choose “Accept” or “Decline.” To make more detailed choices, choose “Customize.”

Trusted identity propagation with Amazon Redshift - AWS IAM Identity Center

Trusted identity propagation with Amazon Redshift

The steps to enable trusted identity propagation depend on whether your users interact with AWS managed applications or customer managed applications. The following diagram shows a trusted identity propagation configuration for client-facing applications - either AWS managed or external to AWS - that query Amazon Redshift data with access control provided either by Amazon Redshift or by authorization services, such as AWS Lake Formation or Amazon S3 Access Grants.

Diagram of trusted identity propagation using Amazon Redshift, Amazon QuickSight, Lake Formation, and IAM Identity Center

When trusted identity propagation to Amazon Redshift is enabled, Redshift administrators can configure Redshift to automatically create roles for IAM Identity Center as the identity provider, map Redshift roles to groups in IAM Identity Center, and use Redshift role-based access control to grant access.

Supported client-facing applications

AWS managed applications

The following AWS managed client-facing applications support trusted identity propagation to Amazon Redshift:

Note

If you're using Amazon Redshift Spectrum to access external databases or tables in AWS Glue Data Catalog, consider setting up Lake Formation and Amazon S3 Access Grants to provide fine-grain access control.

Customer managed applications

The following customer managed applications support trusted identity propagation to Amazon Redshift:

PrivacySite termsCookie preferences
© 2025, Amazon Web Services, Inc. or its affiliates. All rights reserved.