AWS SSO + Azure AD, no way to access AWS Console?

0

I am trying to access the AWS Console via AWS SSO with Azure AD as my identity provider. Following this Microsoft tutorial: https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/aws-single-sign-on-tutorial, I was able to successfully set up SSO and automatic provisioning. To initiate sign in I use the My App browser extension. I can authenticate but I am brought to the User Portal and I have no applications. What am I missing? How do I access the AWS Console using this method?

Microsoft has another Enterprise Application call AWS Single-Account Access. If I set this up, I can access the Console: https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/amazon-web-service-tutorial but I don't think that's what I want. Any help would be much appreciated. Thanks

1개 답변
2
수락된 답변

You are missing granting your AWS SSO users/groups access to the accounts. Assign User Access

AWS
답변함 2년 전
  • What Michael said. You have configured a federated link from AAD to AWS SSO, but now you need to log into the Root Account of your AWS Org (where AWS SSO is configured) and assign users access to AWS accounts. This is done through the assignment of Permission Sets to users/groups and AWS accounts. Think of Permission Sets as JSON templates with which IAM Roles are created in the targetted AWS account(s).

  • That was it, thanks!

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인