
l3uqy (l3uqy) asked a question.
Hi, I would like to transform the group description to get the account Id, rather than including the account Id in the group/role name, such as aws*my-account*my-role*123456789. Instead, I would like to include the account Id in the group's description, then get that during a SAML request and transform the ARN based on the group name AND parsing out the account ID from the group description. Is this possible?

Hi Don,
This is Alex from Okta Support.
Based on the information you provided it does not seem like this would be achievable. But I recommend opening a ticket with us to further investigate your setup.
Best regards,