<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008OMgy9SADOkta Classic EngineIntegrationsAnswered2018-11-02T20:01:57.000Z2018-10-02T05:56:59.000Z2018-11-02T20:01:57.000Z
  • Hi Andrew,

     

    Roles in AWS are tied to policies, which are tied to the resources they control. To assume that Role, you have to establish a session with AWS, for which you need to have security credentials that are comprised of access keys and session tokens associated with the keys. As part of the integration, Okta takes in those keys and makes APIs call to establish that session, then gives permissions to users within AD security groups. For the end-user this is all seamless as they just need to provide the keys to Okta. Okta does the authentication, then provides access control to AWS users.

     

    More details here : https://support.okta.com/help/s/article/25052756-Amazon-Web-Services-AWS-IAM-Deployment-Guide

    And here under Step 5 : https://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Amazon-Web-Service

     

    If you need further assistance on this, feel free to submit a ticket and my colleagues will be right here to assist.

     

    Bogdan Radu

    Technical Support Engineer

    Okta Global Customer Care

    Expand Post
    Selected as Best
  • Hi Andrew,

     

    Roles in AWS are tied to policies, which are tied to the resources they control. To assume that Role, you have to establish a session with AWS, for which you need to have security credentials that are comprised of access keys and session tokens associated with the keys. As part of the integration, Okta takes in those keys and makes APIs call to establish that session, then gives permissions to users within AD security groups. For the end-user this is all seamless as they just need to provide the keys to Okta. Okta does the authentication, then provides access control to AWS users.

     

    More details here : https://support.okta.com/help/s/article/25052756-Amazon-Web-Services-AWS-IAM-Deployment-Guide

    And here under Step 5 : https://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Amazon-Web-Service

     

    If you need further assistance on this, feel free to submit a ticket and my colleagues will be right here to assist.

     

    Bogdan Radu

    Technical Support Engineer

    Okta Global Customer Care

    Expand Post
    Selected as Best
  • Hi Support,

     

    I understand the basics around how the integration works, we have set it up and are using it currently.

     

    My question is "Can I use Okta's API to make changes to the AWS account list in the integration?"

     

    -Andrew

    Expand Post
This question is closed.
Loading
AWS Integration, adding accounts