issues with AWS SSO linking to Google Workspaces

0

After following this tutorial step by step https://aws.amazon.com/blogs/security/how-to-use-g-suite-as-external-identity-provider-aws-sso/ I get a 403 error every time

  1. That’s an error. Error: app_not_configured_for_user Service is not configured for this user.

I double checked every field and Identity especially and nothing seems to point where the issue is coming from.

Any tips for debugging?

질문됨 2년 전3149회 조회
4개 답변
1
수락된 답변

Sorry for answering this myself. While the other answers are indeed correct my issue was totally unrelated and was most likely to the work google workspaces works. After 24 hours from setting up the connection it started working by itself. Writing this just in case others run into this issue. If you are 100% sure you set everything according to the article and still get the error, have some patience, it will work.

답변함 2년 전
0

Based on the error prompt & as per my understanding, this points out the need for additional settings on the Google Apps account. Can you verify that the value in the saml:Issuer tag in the SAMLRequest matches the Entity ID value configured in the SAML Service Provider Details section in the Admin console. This value is case-sensitive.

profile pictureAWS
지원 엔지니어
답변함 2년 전
  • Well the entities and other values were transferred via the IdP file as in the tutorial and was values are all lowercase. Is there any way to actually check the SAML Request?

0

I've set this up recently and have seen that error. From what I understand it means the user you are logged in with\ trying to log in with does not have access to the SAML app you configured in Google Workspaces. From experience this can happen because you are already logged into a different Google account that does not have access or you have not configured your SAML app in Google Workspaces to allow the user have you logged in with access to it.

In the blog post under step 7 it directs you to "select ON for everyone", have you done that? Or otherwise have you configured an Organizational Unit or Group to have access that your user is not part of?

답변함 2년 전
0

The trick is to make the Google account you want to use with AWS your default Google account. You do that by clicking "Sign out of all accounts" in Google, and then, first login to the account you want to use as the default account, and then login with your secondary accounts.

Benoit
답변함 4일 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠