<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

How to Integrate Amazon Web Service China Instance via User Groups

Single Sign-On
Okta Integration Network
Okta Classic Engine

Overview

This article explains how to configure the Amazon Web Services Application from Okta Integration Network for AWS China using user groups, detailing the SAML 2.0 setup and region-specific nuances.

Applies To

  • Okta Classic Engine
  • Amazon Web Services SAML 2.0
  • AWS China
  • User Groups

Solution

To use the Amazon Web Services Application from Okta Integration Network for AWS China via user groups, follow these steps:

  1. Go to the Okta Admin panel and then Application > Amazon Web Services App Sign On >  ACS URL (optional and only relevant to SAML SSO).

  2. Insert the following link in the field https://signin.amazonaws.cn/saml.

  3. Click Save

  4. Enable Use Group Mapping.

  5. Make sure that the Role Value Pattern is set in the following format: 

    arn:aws-cn:iam::${accountid}:saml-provider/OKTA,arn:aws-cn:iam::${accountid}:role/${role}
    
  6. Click Save.
    Advanced settings 

NOTE: Please note the extra -cn that was added to:

arn:aws:iam::${accountid}:saml-provider/OKTA,arn:aws:iam::${accountid}:role/${role}
 

Role Value Pattern

AWS services or capabilities described in AWS documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with AWS services in China.

Related References

Loading
Okta Support - How to Integrate Amazon Web Service China Instance via User Groups