About This Architecture
AWS Transfer Family with custom identity provider integrates SFTP/FTP clients through a VPC endpoint, delegating authentication to a Lambda function backed by Cognito User Pool and SSM Parameter Store. The Transfer Server routes authenticated users to S3 buckets with logical directory mappings, enforcing least-privilege access via IAM roles for Transfer, Lambda execution, and CloudWatch logging. This architecture eliminates managed user overhead while maintaining audit trails and fine-grained access control. Fork and customize this diagram on Diagrams.so to adapt the identity provider logic, add additional storage backends, or modify security group rules for your compliance requirements.