<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
AWS Session Token Lifetime in SAML Authentication
Single Sign-On
Okta Classic Engine
Okta Identity Engine
Overview

This article discusses the issue where one AWS integration can support Lifetime Duration and while another one does not support Lifetime Duration. 

Applies To
  • Session Duration
  • Amazon Web Services (AWS)
  • Secure Assertion Markup Language (SAML)
Cause

That is happening because there are two AWS integrations in the application catalog: one that supports Lifetime Duration (AWS Account Federation) and one that does not via the SAML attribute (AWS IAM Identity Center).

Solution

To have access to the Session Duration option in the Sign On tab of the application, the AWS Account Federation application needs to be integrated, and not the AWS IAM Identity Center.

Loading
AWS Session Token Lifetime in SAML Authentication