Password reset using AWS SSO with external identity provider (AD)

0

Hello everyone,

My Organization uses AWS SSO with on-premise Active Directory as an external Identity Source. In detail, there is an AWS Managed AD in TWO-WAY-TRUST with the on-premise AD. All users reside in the on-premises AD, the one on the AWS side is just a bridge. The on-premise AD for security reasons imposes the password reset of the users every 3 months, consequently the users are cut off from AWS repeatedly. This happens because the AWS SSO console does not allow password reset with external identity sources and returns a generic error. Has anyone managed to find a solution/workaround for resetting the password via SSO and external identity source? I've been looking for a solution to this problem for some time to no avail.

Thank you

1개 답변
0

I am not exactly sure how the AWS IAM Identity Center (previously called AWS SSO) is configured to connect with your on-premise AD. No password information is synchronized to IAM Identity Center; only the users, group and membership information is synchronized to IAM Identity Center.

===Extracted the IAM Identity Center documentation ===

IAM Identity Center uses the connection provided by the AWS Directory Service to synchronize user, group, and membership information from your source directory in Active Directory to the IAM Identity Center identity store. No password information is synchronized to IAM Identity Center, since user authentication takes place directly from the source directory in Active Directory.

AWS
답변함 일 년 전
  • That's right Ronald and thanks for the feedback. The point is exactly that, implement a password reset mechanism that interacts with Active Directory (if possible). Currently, every 3 months a user must contact the supplier who manages the AD to request a password change.

  • You can search for Self-Service Password Reset for Active Directory. There are a number of software/tool available.

  • Thanks for the feedback Roanld. I am aware of these software, the idea was not to use third-party software but to make it possible for users to carry out the procedure via the SSO page. Apparently I do not believe there alternative.

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠