AWS SSO

更新时间:
复制 MD 格式

This guide explains how to set up single sign-on to AWS by using Alibaba Cloud IDaaS.

Procedure

1. Configure Alibaba Cloud IDaaS

  1. Create an AWS application.

    1. Log on to the IDaaS console, select your Alibaba Cloud IDaaS instance, and in the Actions column, click Console.

    2. Go to Applications > Add Application > Marketplace, search for AWS SSO, and click Add Application.

    3. Confirm the application name and click Add.

  2. On the Sign-In > SSO tab, configure the following parameters:

    Parameter

    Description

    SSO

    Set to Enabled.

    AWS SSO Sign-in URL

    Enter the AWS Access Portal Sign-in URL provided by AWS IAM Identity Center.

    AWS SSO ACS URL

    Enter the IAM Identity Center Assertion Consumer Service (ACS) URL provided by AWS IAM Identity Center.

    AWS SSO Issuer URL

    Enter the IAM Identity Center Issuer URL provided by AWS IAM Identity Center.

    Application User

    Select an option based on your requirements. This guide uses Prefer Application Username and Use IDaaS Username as Backup as an example.

    Authorize

    Select Manually or All Users based on your requirements. For testing, we recommend selecting All Users for Authorize to skip assigning permissions to Alibaba Cloud IDaaS accounts.

  3. Obtain identity provider information. Use one of the following methods:

    1. Method 1: In the Application Settings section, download the IdP Metadata to configure the AWS identity provider's IdP SAML metadata.

    2. Method 2: Obtain the IdP SSO URL and IdP Entity ID. You will use these values to configure the IdP Sign-in URL and IdP Issuer URL in AWS.

  4. Public key certificate. Download or copy the certificate, and then import or paste it into the AWS configuration.

  5. Assign user access permissions. On the Application User tab, click Add Application User.

    Important

    The identity name used to access the application must exactly match the username configured in AWS.

2. Configure AWS

  1. Log on to the AWS platform.

  2. In the upper-right corner, click My Account and select Management Console.

  3. In the search bar, enter IAM and select IAM Identity Center.

  4. In the dashboard, go to Configuration, select the Identity Providers tab, and click Actions > Change Identity Source.

  5. Change the identity source to External Identity Provider, and then click Next.

  6. Copy the AWS Access Portal Sign-in URL, IAM Identity Center Assertion Consumer Service (ACS) URL, and IAM Identity Center Issuer URLfrom the service provider metadata, and paste them into the AWS SSO Sign-in URL, AWS SSO ACS URL, and AWS SSO Issuer URL fields in your Alibaba Cloud IDaaS application, respectively.

  7. Paste the IdP SSO URL and IdP Entity ID from your Alibaba Cloud IDaaS application into the IdP Sign-in URL and IdP Issuer URL fields in AWS, respectively. Alternatively, upload the IdP Metadata file from Alibaba Cloud IDaaS to the IdP SAML metadata section. For the IdP certificate, click Select File and upload the Certificate file. When finished, click Next.

  8. Review and confirm the identity source change.

  9. Create a new user. In the left-side navigation pane, click Users, and then click Add User. Follow the prompts to enter the user details.

  10. Authorize the user.

    1. In the left-side navigation pane, go to Multi-account Permissions > AWS Accounts and click Manage Account.

    2. Click Assign users or groups.

    3. Click the Users tab, enter and select the user that you want to authorize, and then click Next.

    4. Click Create Permission Set. Select the required permissions based on your business needs. This example uses the AdministratorAccess permission set. After making your selection, click Next.

    5. On the review and submit page, confirm the user and permissions, and then click Submit.

3. Verify SSO

  1. IdP-initiated SSO

    Log on to the Alibaba Cloud IDaaS application portal with an account that has permissions for the AWS SSO application. Click the application icon to initiate single sign-on. This action logs you on to AWS as a federated user.

  2. SP-initiated SSO

    In AWS IAM Identity Center, obtain the AWS Access Portal URL.

    Open the AWS Access Portal URL in an incognito browser window. If you are already logged on to the Alibaba Cloud IDaaS application portal, you will be automatically logged in to AWS as a federated user. If not, you will be redirected to the Alibaba Cloud IDaaS logon page. On this page, enter your credentials and click Log on. After logging on to Alibaba Cloud IDaaS, you are automatically logged in to AWS.