AWS Transfer Family Custom Identity Provider — MULTI architecture diagram

About This Architecture

AWS Transfer Family with custom identity provider integrates SFTP/FTP clients through a VPC endpoint, delegating authentication to a Lambda function backed by Cognito User Pool and SSM Parameter Store. The Transfer Server routes authenticated users to S3 buckets with logical directory mappings, enforcing least-privilege access via IAM roles for Transfer, Lambda execution, and CloudWatch logging. This architecture eliminates managed user overhead while maintaining audit trails and fine-grained access control. Fork and customize this diagram on Diagrams.so to adapt the identity provider logic, add additional storage backends, or modify security group rules for your compliance requirements.

People also ask

How do I set up AWS Transfer Family with a custom identity provider using Lambda and Cognito?

This diagram shows how to configure AWS Transfer Family with a Lambda-based custom identity provider that authenticates users against Cognito User Pool and retrieves public keys from S3. The Transfer Server routes authenticated clients to S3 buckets using logical directory mappings enforced by IAM roles, with all access logged to CloudWatch.

AWS Transfer Family Custom Identity Provider

MultiadvancedAWS Transfer FamilySFTPLambdaCognitoS3IAM
Domain: Cloud AwsAudience: AWS solutions architects designing secure file transfer infrastructure with custom identity providers
2 views0 favoritesPublic

Created by

July 12, 2026

Updated

August 3, 2026 at 12:51 PM

Type

network

Need a custom architecture diagram?

Describe your architecture in plain English and get a production-ready Draw.io diagram in seconds. Works for AWS, Azure, GCP, Kubernetes, and more.

Generate with AI

AI-generated. Verify before production use. Learn more

Report this diagram