<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AWS IAM Identity Center &#8211; Blog of Kliment Andreev &#8211; A place so I won&#039;t forget things</title>
	<atom:link href="https://blog.andreev.it/tag/aws-iam-identity-center/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.andreev.it</link>
	<description></description>
	<lastBuildDate>Wed, 20 Mar 2024 17:25:23 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>Okta and AWS SSO (AWS IAM Identity Center)</title>
		<link>https://blog.andreev.it/2024/03/okta-and-aws-sso-aws-iam-identity-center/</link>
					<comments>https://blog.andreev.it/2024/03/okta-and-aws-sso-aws-iam-identity-center/#respond</comments>
		
		<dc:creator><![CDATA[Kliment Andreev]]></dc:creator>
		<pubDate>Wed, 20 Mar 2024 17:25:23 +0000</pubDate>
				<category><![CDATA[AWS]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[AWS IAM Identity Center]]></category>
		<category><![CDATA[OKTA]]></category>
		<category><![CDATA[SSO]]></category>
		<guid isPermaLink="false">https://blog.andreev.it/?p=9783</guid>

					<description><![CDATA[In this post I&#8217;ll describe how to integrate Okta and your AWS account. In&#8230;]]></description>
										<content:encoded><![CDATA[<div id="bsf_rt_marker"></div><p>In this post I&#8217;ll describe how to integrate Okta and your AWS account. In order everything to work, you&#8217;ll have to enable AWS Organization on the master account and then you can add multiple sub accounts in AWS.<br />
Best practice says that the AWS master account should be used for SSO only and you shouldn&#8217;t run any workloads. First thing first, let&#8217;s start with Okta. </p>
<h1>Okta</h1>
<p>Log to your Okta account or sign up for a 30 day trial. Once logged in, if you haven&#8217;t already done so, change the sign-in domain from trail*-okta.com to your domain. Or you can skip this step.<br />
Click on <strong>Admin </strong>from the upper right corner and then under <strong>Customizations</strong>, click on <strong>Domain</strong>. I&#8217;ve used the Okta-managed customization because it&#8217;s easier to manage.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-01.png"><img fetchpriority="high" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-01-1024x507.png" alt="" width="1024" height="507" class="aligncenter size-large wp-image-9784" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-01-1024x507.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-01-300x148.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-01-768x380.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-01-1536x760.png 1536w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-01-2048x1014.png 2048w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-01-1920x950.png 1920w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-01-1170x579.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-01-585x290.png 585w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
After you click <strong>Next</strong>, you&#8217;ll be prompted to add two DNS entries for your domain.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-02.png"><img decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-02-1024x575.png" alt="" width="1024" height="575" class="aligncenter size-large wp-image-9785" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-02-1024x575.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-02-300x168.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-02-768x431.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-02-1536x862.png 1536w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-02-1200x675.png 1200w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-02-1170x657.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-02-585x328.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-02.png 1579w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
Change the DNS. This will allow us to access Okta dashboard using our domain in my case it&#8217;s okta.andreev.it. From the same menu on the left, click on <strong>Applications</strong>, then <strong>Applications </strong>again and click on <strong>Browse App Catalog</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-03.png"><img decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-03-1024x584.png" alt="" width="1024" height="584" class="aligncenter size-large wp-image-9824" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-03-1024x584.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-03-300x171.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-03-768x438.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-03-1170x668.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-03-585x334.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-03.png 1230w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
Search for <strong>AWS IAM</strong> and choose <strong>AWS IAM Identity Center</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-04.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-04-1024x477.png" alt="" width="1024" height="477" class="aligncenter size-large wp-image-9825" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-04-1024x477.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-04-300x140.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-04-768x358.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-04-585x273.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-04.png 1120w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
Click on <strong>Add Integration</strong> and then <strong>Done</strong>.<br />
Click on the<strong> Sign On</strong> tab and scroll all the way down to <strong>SAML Signing Certificates</strong>. Click on <strong>Actions </strong>drop-down and then <strong>View IdP metadata</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-05.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-05-1024x386.png" alt="" width="1024" height="386" class="aligncenter size-large wp-image-9830" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-05-1024x386.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-05-300x113.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-05-768x290.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-05-1170x441.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-05-585x221.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-05.png 1228w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
This will open a new tab with an XML file. Save the file as <em>metadata.xml</em>.</p>
<h1>AWS</h1>
<p>Go to console.aws.amazon.com and log with your root account. Go to <strong>IAM Identity Center</strong> and click on <strong>Enable</strong> and then select  <strong>Enable with AWS Organizations</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-06.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-06.png" alt="" width="594" height="357" class="aligncenter size-full wp-image-9831" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-06.png 594w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-06-300x180.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-06-585x352.png 585w" sizes="(max-width: 594px) 100vw, 594px" /></a><br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-07.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-07-1024x789.png" alt="" width="1024" height="789" class="aligncenter size-large wp-image-9832" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-07-1024x789.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-07-300x231.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-07-768x591.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-07-1170x901.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-07-585x450.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-07.png 1309w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
Click on <strong>Settings </strong>on the left, then <strong>Actions </strong>drop-down and click on <strong>Customize AWS access portal URL</strong>. Change the URL so it&#8217;s something that you can easily remember, e.g. yourorg or aws-master.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-10.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-10-1024x354.png" alt="" width="1024" height="354" class="aligncenter size-large wp-image-9836" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-10-1024x354.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-10-300x104.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-10-768x266.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-10-1536x532.png 1536w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-10-2048x709.png 2048w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-10-1920x664.png 1920w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-10-1170x405.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-10-585x202.png 585w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
Click on <strong>Settings </strong>on the left, then <strong>Actions </strong>drop-down and click on <strong>Change identity source</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-08.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-08-1024x320.png" alt="" width="1024" height="320" class="aligncenter size-large wp-image-9833" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-08-1024x320.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-08-300x94.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-08-768x240.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-08-1536x481.png 1536w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-08-2048x641.png 2048w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-08-1920x601.png 1920w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-08-1170x366.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-08-585x183.png 585w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
Choose <strong>External identity provider</strong> and click <strong>Next</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-09.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-09-1024x579.png" alt="" width="1024" height="579" class="aligncenter size-large wp-image-9834" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-09-1024x579.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-09-300x170.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-09-768x434.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-09-1170x663.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-09-585x331.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-09.png 1291w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
You&#8217;ll land on a page with two parts, <em>Service provider metadata</em> (that&#8217;s AWS) and <em>Identity provider metadata</em> (that&#8217;s Okta).<br />
Click on <strong>Download metadata file</strong> from upper right. You&#8217;ll need this in Okta. The file will be named with some date prefix and some characters plus metadata.xml<br />
Copy the values for the 2nd and 3rd entry. You&#8217;ll also need these for Okta.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-11.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-11-1024x296.png" alt="" width="1024" height="296" class="aligncenter size-large wp-image-9838" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-11-1024x296.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-11-300x87.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-11-768x222.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-11-585x169.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-11.png 1155w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
Click on <strong>Choose file</strong> under <em>Identity provider metadata</em> and upload the <em>metadata.xml</em> file that you&#8217;ve downloaded earlier from Okta.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-12.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-12.png" alt="" width="649" height="319" class="aligncenter size-full wp-image-9839" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-12.png 649w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-12-300x147.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-12-585x288.png 585w" sizes="(max-width: 649px) 100vw, 649px" /></a><br />
Click <strong>Next</strong>, type <strong>ACCEPT </strong>and finally click <strong>Change identity source</strong>.</p>
<h1>Okta</h1>
<p>Go back to Okta, <strong>Sign On</strong> tab and right bellow click <strong>Edit</strong>. Enter the two URL entries that you copied from AWS. Click <strong>Save </strong>after.</p>
<h1>AWS</h1>
<p>Go back to AWS, then <strong>IAM Identity Center</strong>, click on <strong>Settings </strong>and click to <strong>Enable </strong>the <em>Automatic Provisioning</em>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-14.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-14-1024x144.png" alt="" width="1024" height="144" class="aligncenter size-large wp-image-9841" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-14-1024x144.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-14-300x42.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-14-768x108.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-14-1536x216.png 1536w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-14-2048x287.png 2048w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-14-1920x269.png 1920w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-14-1170x164.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-14-585x82.png 585w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
Click on <strong>Show Token</strong> and copy both values for the <strong>SCIM endpoint </strong>and the <strong>Access Token</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-15.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-15-1024x632.png" alt="" width="1024" height="632" class="aligncenter size-large wp-image-9842" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-15-1024x632.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-15-300x185.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-15-768x474.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-15-1170x722.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-15-585x361.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-15.png 1216w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></p>
<h1>Okta</h1>
<p>Go back to Okta and for the AWS app, click on <strong>Provisioning </strong>and then click on <strong>Configure API Integration</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-16.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-16-1024x759.png" alt="" width="1024" height="759" class="aligncenter size-large wp-image-9843" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-16-1024x759.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-16-300x222.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-16-768x569.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-16-1170x867.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-16-585x434.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-16.png 1345w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
Click <strong>Enable API Integration</strong> and enter the SCIM endpoint and the token value in the corresponding fields. Click <strong>Save</strong>. Remove the trailing slash from the end of the Base URL (SCIM endpoint) if you get an error (<em>Base URL: Does not match required pattern</em>)<br />
Under <strong>Provisioning </strong>tab, click on <strong>To App</strong>, click <strong>Edit </strong>and select all three checkmarks. Click <strong>Save</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-18.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-18-1024x755.png" alt="" width="1024" height="755" class="aligncenter size-large wp-image-9844" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-18-1024x755.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-18-300x221.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-18-768x567.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-18-1536x1133.png 1536w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-18-1170x863.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-18-585x432.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-18.png 1575w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
Then, go to <strong>Assignments </strong>tab and assign a group or a user to this AWS app.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-19.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-19-1024x441.png" alt="" width="1024" height="441" class="aligncenter size-large wp-image-9846" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-19-1024x441.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-19-300x129.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-19-768x331.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-19-1170x504.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-19-585x252.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-19.png 1222w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></p>
<h1>AWS</h1>
<p>Go back to AWS and under <strong>IAM Identity Center</strong> and then <strong>Users</strong>, you can see the user that we just assigned.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-20.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-20-1024x337.png" alt="" width="1024" height="337" class="aligncenter size-large wp-image-9847" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-20-1024x337.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-20-300x99.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-20-768x253.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-20-1170x385.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-20-585x193.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-20.png 1279w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
But this user has no rights in AWS, so we have to create a Permission set and then assign this user to that permission set and the account that this user has access to. Click on <strong>Permission sets</strong> on the left and then <strong>Create permission set</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-21.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-21-1024x381.png" alt="" width="1024" height="381" class="aligncenter size-large wp-image-9848" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-21-1024x381.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-21-300x112.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-21-768x286.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-21-585x218.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-21.png 1050w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
I chose <strong>AdministratorAccess </strong>from the <strong>Predefined permission sets</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-22.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-22.png" alt="" width="657" height="616" class="aligncenter size-full wp-image-9849" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-22.png 657w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-22-300x281.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-22-585x548.png 585w" sizes="(max-width: 657px) 100vw, 657px" /></a><br />
Go back to <strong>AWS accounts</strong>, click on the account and choose <strong>Assign users or groups</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-23.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-23-1024x380.png" alt="" width="1024" height="380" class="aligncenter size-large wp-image-9850" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-23-1024x380.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-23-300x111.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-23-768x285.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-23-1536x570.png 1536w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-23-1170x434.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-23-585x217.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-23.png 1642w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
Select the <strong>User</strong> tab, click on the user, click <strong>Next</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-24.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-24-1024x641.png" alt="" width="1024" height="641" class="aligncenter size-large wp-image-9851" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-24-1024x641.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-24-300x188.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-24-768x481.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-24-1170x732.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-24-585x366.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-24.png 1270w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
Select the permission set that we just created and click <strong>Next </strong>then <strong>Submit</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-25.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-25.png" alt="" width="766" height="582" class="aligncenter size-full wp-image-9852" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-25.png 766w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-25-300x228.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-25-585x444.png 585w" sizes="(max-width: 766px) 100vw, 766px" /></a><br />
We just told AWS that the user xyz will have access to the account abc with AdministratorAccess permissions.</p>
<h1>Test SSO</h1>
<p>Open a new tab and go to the URL that you configured earlier (<em>Customize AWS access portal</em>). It should be https://whatever.awsapps.com/start.<br />
AWS will redirect you to Okta where you&#8217;ll enter your Okta username.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-26.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-26.png" alt="" width="693" height="886" class="aligncenter size-full wp-image-9853" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-26.png 693w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-26-235x300.png 235w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-26-585x748.png 585w" sizes="(max-width: 693px) 100vw, 693px" /></a><br />
Once authenticated, you&#8217;ll see the AWS accounts in your org and the permissions that you have.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P170-27.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P170-27.png" alt="" width="904" height="577" class="aligncenter size-full wp-image-9854" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P170-27.png 904w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-27-300x191.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-27-768x490.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P170-27-585x373.png 585w" sizes="(max-width: 904px) 100vw, 904px" /></a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.andreev.it/2024/03/okta-and-aws-sso-aws-iam-identity-center/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Entra ID (Azure AD) and AWS SSO (AWS IAM Identity Center)</title>
		<link>https://blog.andreev.it/2024/03/entra-id-azure-ad-and-aws-sso/</link>
					<comments>https://blog.andreev.it/2024/03/entra-id-azure-ad-and-aws-sso/#respond</comments>
		
		<dc:creator><![CDATA[Kliment Andreev]]></dc:creator>
		<pubDate>Mon, 11 Mar 2024 18:58:39 +0000</pubDate>
				<category><![CDATA[AWS]]></category>
		<category><![CDATA[Azure]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[AWS IAM Identity Center]]></category>
		<category><![CDATA[Azure AD]]></category>
		<category><![CDATA[entra ID]]></category>
		<category><![CDATA[SSO]]></category>
		<guid isPermaLink="false">https://blog.andreev.it/?p=9787</guid>

					<description><![CDATA[I wrote about this topic a couple of years ago, but some things changed&#8230;]]></description>
										<content:encoded><![CDATA[<div id="bsf_rt_marker"></div><p>I wrote about this <a href="https://blog.andreev.it/2021/06/azure-aws-use-azure-ad-with-aws-sso/" rel="noopener" target="_blank">topic </a>a couple of years ago, but some things changed so I am writing this post again. In this post I&#8217;ll explain how to log to AWS Console and AWS cli with Entra ID (former Azure AD) credentials. For this you&#8217;ll need admin access to both the AWS account and Entra ID. </p>
<h1>IAM Identity Center</h1>
<p>The former AWS Single Sign-on is now IAM Identity Center. You need to enable this in order to configure SSO. Go to <strong>IAM Identity Center</strong> and click on the <strong>Enable</strong> button.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P171-01.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P171-01-1024x277.png" alt="" width="1024" height="277" class="aligncenter size-large wp-image-9788" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P171-01-1024x277.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-01-300x81.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-01-768x208.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-01-1536x415.png 1536w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-01-1170x316.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-01-585x158.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-01.png 1887w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
Enable it with AWS Organizations.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P171-02.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P171-02-1024x828.png" alt="" width="1024" height="828" class="aligncenter size-large wp-image-9789" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P171-02-1024x828.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-02-300x243.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-02-768x621.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-02-1170x947.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-02-585x473.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-02.png 1246w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
What you want to do first is to change the AWS access portal URL. Click on the <strong>Edit </strong>button and change the URL. It has to be unique, so don&#8217;t expect you can type aws and be done with it. </p>
<p><a href="https://blog.andreev.it/wp-content/uploads/2024/03/P171-03-1.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P171-03-1.png" alt="" width="796" height="823" class="aligncenter size-full wp-image-9821" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P171-03-1.png 796w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-03-1-290x300.png 290w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-03-1-768x794.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-03-1-585x605.png 585w" sizes="(max-width: 796px) 100vw, 796px" /></a></p>
<p>Another setting that you have to change is the <strong>Identity source</strong>. On the left side of the <strong>IAM Identity Center</strong>, you are on the <strong>Dashboard </strong>screen. Click on <strong>Settings </strong>and then click on <strong>Change identity source</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P171-04.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P171-04-1024x450.png" alt="" width="1024" height="450" class="aligncenter size-large wp-image-9791" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P171-04-1024x450.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-04-300x132.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-04-768x337.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-04-1536x675.png 1536w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-04-2048x900.png 2048w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-04-1920x844.png 1920w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-04-1170x514.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-04-585x257.png 585w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
Choose <strong>External identity provider</strong> and click <strong>Next</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P171-05.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P171-05-1024x539.png" alt="" width="1024" height="539" class="aligncenter size-large wp-image-9792" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P171-05-1024x539.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-05-300x158.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-05-768x404.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-05-1170x616.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-05-585x308.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-05.png 1305w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
You will see this screen which consists of two parts, service provider metatada (that&#8217;s AWS) and Identity provider metadata (that&#8217;s Entra ID). Click on <strong>Download metadata file</strong>. You&#8217;ll get an XML file.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P171-06.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P171-06-906x1024.png" alt="" width="906" height="1024" class="aligncenter size-large wp-image-9793" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P171-06-906x1024.png 906w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-06-265x300.png 265w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-06-768x868.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-06-1170x1323.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-06-585x661.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-06.png 1239w" sizes="(max-width: 906px) 100vw, 906px" /></a><br />
Keep the page open and in a new browser window go to portal.azure.com.</p>
<h1>Entra ID</h1>
<p>Once logged to Azure, go to <strong>Enterprise Applications</strong> and search for <strong>AWS IAM Identity Center (successor to AWS Single Sign-On)</strong>. Click to install. When you are presented with the <strong>Overview </strong>of the application, click on <strong>Assign users and groups</strong>. Depending on your Entra ID level (P1 or P2) you might not be able to assign groups, so you have to assign users.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P171-07.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P171-07-1024x600.png" alt="" width="1024" height="600" class="aligncenter size-large wp-image-9795" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P171-07-1024x600.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-07-300x176.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-07-768x450.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-07-1536x900.png 1536w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-07-2048x1199.png 2048w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-07-1920x1124.png 1920w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-07-1170x685.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-07-585x343.png 585w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
The next step is to setup the SSO. Click on <strong>2. Set up single sign on</strong> and then <strong>SAML</strong>. You&#8217;ll be presented with this page and eventually you&#8217;ll see a prompt if you want to save some SSO settings. If you don&#8217;t see the prompt, no worries. If you see the prompt, click <strong>Yes</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P171-08.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P171-08-814x1024.png" alt="" width="814" height="1024" class="aligncenter size-large wp-image-9798" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P171-08-814x1024.png 814w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-08-238x300.png 238w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-08-768x967.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-08-1170x1473.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-08-585x736.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-08.png 1218w" sizes="(max-width: 814px) 100vw, 814px" /></a><br />
Click on <strong>Upload metadata file</strong> and point to the XML file that you saved from AWS. Click <strong>Save </strong>and don&#8217;t worry about any of the fields there. If you see a popup to test the config, just click <strong>No, I&#8217;ll test later</strong>. Under step 3, <strong>SAML Certificates</strong>, click to <strong>Download </strong>Federation Metadata XML.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P171-09.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P171-09.png" alt="" width="1009" height="546" class="aligncenter size-full wp-image-9799" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P171-09.png 1009w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-09-300x162.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-09-768x416.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-09-585x317.png 585w" sizes="(max-width: 1009px) 100vw, 1009px" /></a><br />
You&#8217;ll get another XML file called <strong>AWS IAM Identity Center (successor to AWS Single Sign-On).xml</strong>.</p>
<h1>Back to AWS</h1>
<p>Go back to the same page where you&#8217;ve downloaded the XML metadata file, but this time look at the bottom part where it says <strong>Identity provider metadata</strong> and <strong>IdP SAML metadata</strong>. Click on <strong>Choose file</strong> and upload the file from Azure. Click <strong>Next</strong>, type <strong>ACCEPT </strong>and click <strong>Change identity source</strong>.<br />
Once completed click to <strong>Enable </strong>Automatic provisioning.  Copy the <strong>SCIM endpoint</strong> and the <strong>access token</strong>. </p>
<h1>Back to Azure</h1>
<p>Under the AWS SSO application. on the left side click on <strong>Provisioning</strong>. Change the <strong>Provisioning Mode</strong> to <strong>Automatic</strong>. Expand <strong>Admin credentials</strong> and for <strong>Tenant ID</strong> enter the <strong>SCIM endpoint</strong> and for <strong>Secret Token</strong>, enter the token. Click <strong>Test Connection</strong> and upon successful test, click <strong>Save</strong>. If you see clientsecret instead of Tenant ID, it means you are not using the right AWS application and you use the AWS Single Account application instead. Start from scratch.<br />
Anytime you assign a new user or a group to AWS application, Azure will sync the user to AWS. But, instead of waiting (40 mins by default) for the initial sync, click on the <strong>Overview </strong>and click <strong>Start provisioning</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P171-10.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P171-10-1024x704.png" alt="" width="1024" height="704" class="aligncenter size-large wp-image-9803" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P171-10-1024x704.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-10-300x206.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-10-768x528.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-10-1170x804.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-10-585x402.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-10.png 1200w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></p>
<h1>Back to AWS</h1>
<p>If your provisioning works fine, you&#8217;ll see your assigned Azure user under <strong>Users </strong>in IAM Identity Center. On the left side of the IAM Identity Center, click on <strong>Permission sets</strong>. Click <strong>Create Permission set</strong> and choose <strong>Predefined permission set</strong>, then <strong>AdministratorAccess</strong>. Change the name, description, session duration if needed and then click <strong>Next</strong> and then <strong>Create</strong>.<br />
Finally, click on <strong>AWS accounts</strong>, select an account from the organization, click <strong>Assign users or groups</strong>, click <strong>Users </strong>or <strong>Groups</strong>, select a user and click <strong>Next</strong>. Assign a permission set, click <strong>Next </strong>and <strong>Submit</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P171-11.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P171-11-1024x675.png" alt="" width="1024" height="675" class="aligncenter size-large wp-image-9804" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P171-11-1024x675.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-11-300x198.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-11-768x506.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-11-585x386.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-11.png 1048w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
Now, test the SSO by going to whatever.awsapps.com/start# and you&#8217;ll be redirected to the Microsoft sign in prompt. Follow the authentication process for Entra ID (username, password, MFA etc) and once you pass the authentication process you&#8217;ll see the AWS account that you have access to.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P171-12.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P171-12-1024x309.png" alt="" width="1024" height="309" class="aligncenter size-large wp-image-9806" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P171-12-1024x309.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-12-300x91.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-12-768x232.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-12-1170x353.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-12-585x177.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-12.png 1513w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></p>
<h1>AWS CLI and SSO</h1>
<p>Follow the instructions to <a href="https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html" rel="noopener" target="_blank">install </a>AWS CLI for your OS, then configure SSO. Name your session, enter the URL you configured earlier, enter the region where you configured SSO and hit enter for the registration scopes. </p>
<pre class="brush: bash; title: ; notranslate">
aws configure sso
SSO session name (Recommended): sso
SSO start URL &#x5B;None]: https://your_url.awsapps.com/start
SSO region &#x5B;None]: us-east-1
SSO registration scopes &#x5B;sso:account:access]:
Attempting to automatically open the SSO authorization page in your default browser.
If the browser does not open or you wish to use a different device to authorize this request, open the following URL:

https://device.sso.us-east-1.amazonaws.com/

Then enter the code:

PWKG-CAFZ
</pre>
<p>After successful authentication, you&#8217;ll be presented with the accounts available to you. Pick one.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2024/03/P171-13.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2024/03/P171-13-1024x305.png" alt="" width="1024" height="305" class="aligncenter size-large wp-image-9819" srcset="https://blog.andreev.it/wp-content/uploads/2024/03/P171-13-1024x305.png 1024w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-13-300x89.png 300w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-13-768x229.png 768w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-13-1536x458.png 1536w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-13-1170x349.png 1170w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-13-585x174.png 585w, https://blog.andreev.it/wp-content/uploads/2024/03/P171-13.png 1734w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><br />
You&#8217;ll be prompted to choose the roles available to you and then specify your default region, default output and the profile. \<br />
NOTE: If you&#8217;ll be working with multiple accounts, maybe you should specify a different profile than the default. It&#8217;s up to you. E.g. specify prod and dev profiles. </p>
<pre class="brush: plain; title: ; notranslate">
There are 2 AWS accounts available to you.
Using the account ID 123456789012
The only role available to you is: AdministratorAccess
Using the role name &quot;AdministratorAccess&quot;
CLI default client Region &#x5B;None]: us-east-2
CLI default output format &#x5B;None]: json
CLI profile name &#x5B;AdministratorAccess-123456789012]: default

To use this profile, specify the profile name using --profile, as shown:

aws s3 ls --profile default
</pre>
<p>After your SSO session expires, you have to log back in.</p>
<pre class="brush: bash; title: ; notranslate">
aws sso login
</pre>
<p>If you are like me and always uses the <strong>default </strong>profile so I don&#8217;t have to type <em>&#8211;profile</em> parameter, then anytime you want to use a different account, just <strong>aws configure sso</strong> again, but specify the other account now. </p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.andreev.it/2024/03/entra-id-azure-ad-and-aws-sso/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
