The following table indicates the current default IAM resource limits.
To change a limit marked as 'Yes' in the 'Adjustable' column, contact our customer support. Please note that, we validate each request before considering a change.
Recommended
| Resource | Level | Default limit | Adjustable |
|---|---|---|---|
Users | Account | 10,000 | Yes |
Groups | Account | 5,000 | Yes |
Groups | User | 8,000 | Yes |
Permissions | Group | 1,000 | Yes |
OAuth clients | Account | 200 | No |
SCIM tokens | Account | 10 | No |
Policies | Account | 200 | No |
Policy statements | Policy | 100 | No |
Groups-to-policy bindings | Account or Environment | 30,000 | No |
Policy boundaries | Account | 2,000 | No |
Boundary assignments per policy | Boundary | 10 | No |
Platform tokens per account | Account | 50,000 | Yes |
Platform tokens per user across all accounts | User | 50 | Yes |
Platform tokens per service user | Account | 200 | Yes |
Workload identity federation trust policies | Account | 50 | Yes |
Service user mappings per trust policy | Trust policy | 1,000 | Yes |
If you exceed the Throttle at limit in the specified time period, you may experience HTTP 429 response status code errors, indicating that you should reduce your request rate.
Recommended
| Resource | Time window | Throttle at | Adjustable |
|---|---|---|---|
OAuth token requests per source IP address | 5 minutes | 1,000 | No |
OAuth token requests per OAuth Client Id | 5 minutes | 150 | No |
The following limits are system-wide and non-adjustable.
| Description | Limit | Adjustable |
|---|---|---|
Concurrent user sessions | 250 | No |
Maximum user session validity | 12 hours | No |
User session inactivity timeout | 1 hour | No |