<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00009TDRqNCAXOkta Classic EngineSingle Sign-OnAnswered2024-08-21T09:01:32.000Z2023-07-20T19:12:48.000Z2023-10-18T15:32:48.000Z

mmjpp (mmjpp) asked a question.

Okta SSO with AWS Identity Centre (Users and Groups Provisioned from AWS)

My work organsiation want us to explore the option of using Okta to SSO into our AWS accounts.

From reading the documentation I understand that IAM Identity Centre will be the best fit. However, it is a requirement of mine to manage the users, groups and permissions within Identity Centre myself and not have Okta provision the user accounts etc.

This would mean I have to raise a ticket and request someone in a different department that is an Okta administrator to either edit user details or add users etc and this in reality is just not practicial because I could be waiting weeks for any progress.

If I were to change the identity source to use external third party Okta, can I still manaully provision, create users, groups and permissions in Identity centre myself and retain that element of control?


  • Paul S. (Okta, Inc.)

    Hello @mmjpp (mmjpp)​ Thank you for reacting out to our Community!

     

    Reviewing the documentation, it seems that would be the case. However this is something on AWS side, rather the Okta side.

    You could use the "AWS Account Federation" application that has the SSO functionality and Provisioning, but it's not true provisioning. In this case you still have access to create users into AWS and manage them.

    Hope this helps.

     

    Community members help others by clicking Like or Select as Best on responses. Try it today.

    Expand Post
    Selected as Best
  • Paul S. (Okta, Inc.)

    Hello @mmjpp (mmjpp)​ Thank you for reacting out to our Community!

     

    Reviewing the documentation, it seems that would be the case. However this is something on AWS side, rather the Okta side.

    You could use the "AWS Account Federation" application that has the SSO functionality and Provisioning, but it's not true provisioning. In this case you still have access to create users into AWS and manage them.

    Hope this helps.

     

    Community members help others by clicking Like or Select as Best on responses. Try it today.

    Expand Post
    Selected as Best
This question is closed.
Loading
Okta SSO with AWS Identity Centre (Users and Groups Provisioned from AWS)