<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00005rczaqSAAOkta Classic EngineOkta Integration NetworkAnswered2024-04-15T10:21:56.000Z2019-01-11T10:58:57.000Z2019-01-14T15:30:48.000Z

cag6q (cag6q) asked a question.

how to Limit SAML Roles returned in AWS Inegration

Okta provides SAML auth for the AWS identity account.

However, Okta syncs ALL roles in the identity account, including those that don't specifically trust this idp. For example the built-in AWS service roles, roles that trust different idps and so on.

 

  • Is it possible to limit or filter the roles synced by an instance of the Okta AWS App?

 


  • Hi Nitin,

     

     

     

    Thank you for reaching out to our community! My name is Dragos and hopefully I can answer your question.

     

     

     

    Currently, there is no way to provide a more granular control on what are the roles imported in Okta from the AWS Schema.

     

    However, there is a thing that you can do. Having multiple Okta groups created and assigning them to the AWS App Instance in Okta, will then provide you with the ability to control what Roles will be assigned to the group and what SAML User Roles as well. Please keep in mind, that, on the "Assign AWS App to Groups" page, the attributes selected will apply to all people assigned to this group.

     

    If this didn't answered your question, you're more than welcomed to create support ticket by navigating to the upper right hand side of the screen and click on "Open a Case".

     

     

     

    Thanks,

     

    Dragos Milea

    Technical Support Engineer

    Okta Global Customer Care

     

    Expand Post
This question is closed.
Loading
how to Limit SAML Roles returned in AWS Inegration