This is bad news for ScaleFT, which provided this service via bastion servers (although not IAM based).
Rackspace managed AWS environments use this for high compliance systems.
The problems it solves are a) that login attempts are logged on a separate system for compliance and b) user management is handled in a centralized way. Both are handled with EC2 Instance Connect.