UpdateInstance
Update the details for the instance of IAM Identity Center that is owned by the AWS account.
In a single UpdateInstance request, you can perform only one of the
following operations:
-
Update the encryption configuration of the instance by specifying
EncryptionConfiguration. -
Enable permission sets for the instance by specifying
PermissionSetsEnabled.
A request that specifies both EncryptionConfiguration and
PermissionSetsEnabled returns a ValidationException. To
perform both operations, call UpdateInstance separately for each. The two
calls can be made in parallel.
Request Syntax
{
"EncryptionConfiguration": {
"KeyType": "string",
"KmsKeyArn": "string"
},
"InstanceArn": "string",
"Name": "string",
"PermissionSetsEnabled": boolean
}
Request Parameters
For information about the parameters that are common to all actions, see Common Parameters.
The request accepts the following data in JSON format.
- EncryptionConfiguration
-
Specifies the encryption configuration for your IAM Identity Center instance. You can use this to configure customer managed KMS keys or AWS owned KMS keys for encrypting your instance data.
Type: EncryptionConfiguration object
Required: No
- InstanceArn
-
The ARN of the instance of IAM Identity Center under which the operation will run. For more information about ARNs, see Amazon Resource Names (ARNs) and AWS Service Namespaces in the AWS General Reference.
Type: String
Length Constraints: Minimum length of 10. Maximum length of 1224.
Pattern:
arn:aws(-[a-z]{1,5}){0,3}:sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}Required: Yes
- Name
-
Updates the instance name.
Type: String
Length Constraints: Minimum length of 0. Maximum length of 255.
Pattern:
[\w+=,.@-]+Required: No
- PermissionSetsEnabled
-
Enables permission sets for this Identity Center instance. The only accepted value is
true. After permission sets are enabled, they cannot be disabled.Note
You can't set
EncryptionConfigurationandPermissionSetsEnabledin the same request. To configure both, make two separateUpdateInstancecalls. These calls can be made in parallel.Type: Boolean
Required: No
Response Elements
If the action is successful, the service sends back an HTTP 200 response with an empty HTTP body.
Errors
For information about the errors that are common to all actions, see Common Error Types.
- AccessDeniedException
-
You do not have sufficient access to perform this action.
- Reason
-
The reason for the access denied exception.
HTTP Status Code: 400
- ConflictException
-
Occurs when a conflict with a previous successful write is detected. This generally occurs when the previous write did not have time to propagate to the host serving the current request. A retry (with appropriate backoff logic) is the recommended response to this exception.
HTTP Status Code: 400
- InternalServerException
-
The request processing has failed because of an unknown error, exception, or failure with an internal server.
HTTP Status Code: 500
- ResourceNotFoundException
-
Indicates that a requested resource is not found.
- Reason
-
The reason for the resource not found exception.
HTTP Status Code: 400
- ThrottlingException
-
Indicates that the principal has crossed the throttling limits of the API operations.
- Reason
-
The reason for the throttling exception.
HTTP Status Code: 400
- ValidationException
-
The request failed because it contains a syntax error.
- Reason
-
The reason for the validation exception.
HTTP Status Code: 400
See Also
For more information about using this API in one of the language-specific AWS SDKs, see the following: