For large enterprises, you would possibly have a microsoft AD No need to create IAM users for each of the employee

If you would want to give temporary access to aws resource using a facebook login - aws cognito… Wow nice