<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
AWS Account Federation Provisioning Settings Removed after LCM SKU Trial Expiration
Okta Classic Engine
Okta Identity Engine
Okta Integration Network
Overview

The Amazon Web Services (AWS) Account Federation application provisioning settings are removed after a Lifecycle Management (LCM) trial subscription expires

Applies To
  • AWS Account Federation  
  • Lifecycle Management (LCM)
Cause

The AWS Account Federation application has a provisioning feature that functions without the Lifecycle Management (LCM) SKU. 

According to Configure the Amazon Web Services Account Federation app in Okta, the Amazon Web Services (AWS) app integration does not support provisioning. This setup under the Provisioning tab is required to provide API access to Okta to download a list of AWS roles to assign during the user assignment. It allows the assignment of multiple roles to users and passes those roles in the SAML assertion.

AWS Account Federation

 

When the trial Lifecycle Management (LCM) SKU is enabled and then expires, the AWS Account Federation API (Application Programming Interface) integration becomes disabled, and the provisioning settings are removed.

Solution

This behavior is expected because removing the license subscription wipes all provisioning settings from all application instances.

However, due to the special nature of the AWS Account Federation application, the provisioning settings can still be enabled to assist with the SAML (Security Assertion Markup Language) single sign-on (SSO) feature.

Loading
AWS Account Federation Provisioning Settings Removed after LCM SKU Trial Expiration