IAM is a "global" service for AWS, where "global" means "it lives in us-east-1".
STS at least has recently started supporting regional endpoints, but most things involving users, groups, roles, and authentication are completely dependent on us-east-1.