- Newest
- Most votes
- Most comments
To add more scopes for an Amazon Q Business application in the Trusted applications for identity propagation, you'll need to follow a process similar to configuring OAuth scopes for other AWS services. However, it's important to note that the specific process for Q Business is not explicitly detailed in the provided information.
Based on similar processes for other AWS services, you would likely need to:
- Open the AWS IAM Identity Center console.
- Navigate to the "Applications" tab and select the "Customer managed" tab.
- Find and select your Amazon Q Business application.
- Look for a section related to "Trusted applications for identity propagation" or "OAuth scopes."
- Choose an option like "Specify trusted applications" or "Update scopes."
- In the configuration process, you should be able to select additional scopes for the application.
However, if Q Business is only showing 3 scopes out of 5 available scopes, there could be a few reasons for this:
- The additional scopes may not be applicable or available for your specific setup or region.
- There might be limitations on which scopes can be added based on your AWS account type or permissions.
- The feature to add all 5 scopes might not be fully rolled out yet.
If you're unable to add the additional scopes through the console, or if you don't see the option to add more scopes, it would be best to contact AWS Support directly. They can provide you with the most up-to-date information on Q Business scope configuration and help you troubleshoot any issues specific to your account or setup.
Sources
Specify trusted applications - AWS IAM Identity Center
Enabling trusted identity propagation in QuickSight - Amazon QuickSight
To add more scopes to the Q Business Application for identity propagation, follow these steps:
Access AWS IAM Identity Center: Log in to the AWS Management Console and navigate to the IAM Identity Center (formerly AWS SSO) service.
Locate Q Business Application: Find Q Business in the list of applications under the "Applications" section.
Review Current Scopes: Check the currently assigned scopes for Q Business. You mentioned it shows 3 out of 5 scopes.
Edit Application Settings: Click on the Q Business application to edit its settings.
Modify Scopes: Look for an option to edit or modify scopes. This might be under a section called "Application properties" or "SAML assertions".
Add Additional Scopes: Select the additional scopes you want to add. The exact names of these scopes may be specific to Q Business, but they could include things like:
read:data write:data admin:access etc. Save Changes: After adding the desired scopes, save your changes.
Update IAM Roles (if necessary): If the new scopes require additional AWS permissions, you may need to update the associated IAM roles.
Verify in Q Business: Log in to Q Business and verify that the new scopes are reflected in the application's permissions.
Test Identity Propagation: Perform a test to ensure that identity propagation works correctly with the new scopes.
Relevant content
- asked 7 months ago
- AWS OFFICIALUpdated 5 months ago
