AWS IAM Identity Center sync issue

0

Hi,

I have Azure AD which is used as Identity source for AWS IAM Identity Center. I created a user in Azure AD and the user synced across AWS IAM Identity Center. But the user is not assigned to one of the groups in AWS IAM Identity Center. This user is assigned to that group in Azure AD. Can you please advise how can I troubleshoot this? Please let me know if the question is not clear.

I checked the document https://docs.aws.amazon.com/singlesignon/latest/userguide/provision-users-from-ad-configurable-ADsync.html#how-it-works-configurable-ADsync but I cannot see Manage Sync option in my IAM Identity Center >> Settings >> Identity Source >> Action.

2回答
1

I assume you are using Azure AD (new name "Entra ID") and integrated with AWS Identity Center by defining an 'Enterprise Application' of 'AWS IAM Identity Center (successor to AWS Single Sign-On)' in Azure. In such a scenario you use SCIM to provision users/groups from Azure to AWS IdC. You can confirm this by looking into your setup, find that Enterprise Application and click it see the "provisioning" configurations.

Please don't mix such a solution with a solution of IdC integration with a Microsoft AD (AWS managed MS AD or AD connector). ADSync that you referred to is applicable for the latter. The former is integrated using SAML, SCIM.

Back to your question of why group is not synced. If your user can be synced but not the group. I am guessing: are you using a free Azure account? With a free account, you can't assign groups to the application (the 'Enterprise Application" you created for AWS IdC in Azure), thus sync will not be done. Check the 3rd paragraph of https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/assign-user-or-group-access-portal?pivots=portal

Please accept answer if it answers your question.

AWS
回答済み 4ヶ月前

ログインしていません。 ログイン 回答を投稿する。

優れた回答とは、質問に明確に答え、建設的なフィードバックを提供し、質問者の専門分野におけるスキルの向上を促すものです。

質問に答えるためのガイドライン

関連するコンテンツ