<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00007QD9yTCATOkta Classic EngineAuthenticationAnswered2026-02-24T09:01:14.000Z2022-02-02T16:51:00.000Z2022-02-03T21:53:47.000Z

zbh36 (zbh36) asked a question.

AWS Client VPN unable to set Authorization Route with Group ID using Okta

AWS SSO using Okta. Working on implementing a AWS Client VPN that also uses the Okta authentication. I've enabled the AWS Client VPN app through Okta and have used the meta-data to create an Identity provider for the Client VPN. I've been able to successfully use the AWS Client VPN, it does the Auth through Okta, so I know that it works. But the Second I change my Authorization Routes in the AWS Client VPN to use a Group ID, I loose access to my resources. I've attempted to use the Okta Group ID, as well as the AWS SSO Group Id provided through Amazon. But neither Group ID seems to take. I've also attempted to put the Group Name in the 'Group ID' field with no success

 

Image is not available


  • zbh36 (zbh36)

    Image is not available
    I was able to get this working. I needed to set the Okta memberOf to `.*` which seems to allow that group information to be passed from Okta -> AWS. This seems like a really weird behavior to me, and I don't know why that isn't the default setting. But there it is.

    Expand Post
    Selected as Best
This question is closed.
Loading
AWS Client VPN unable to set Authorization Route with Group ID using Okta