AWS SSO Google Workspace IDP SCIM


Hi all!
I've been able to configure AWS SSO to with with Google Workspace as it's identity provider using this guide -
I saw that Google isn't a fully supported external identity provider, meaning that it doesn't support automatic provisioning of users/groups from Google Workspace into AWS SSO.

  1. When will the automatic provisioning feature be available for Google Workspace?
  2. In the meantime, what alternatives are there for this feature? I have came across and checked this project,

However, It is no longer available or supported.

Any help will be much appreciated :) ,

Right now that SSO Sync on Github is the best option if you want to automatically synchronize groups from your Google Workspaces to AWS SSO.

We also have a workshop that demonstrates how the SSO Sync can be used to setup integration between AWS SSO and Google Workspaces.

answered 2 months ago
  • I have tried deploying the SSO Sync Github project however, I't seems that this is a dead project for a few reasons.

    1. The last commit was a year ago.
    2. The README link to "AWS Serverless Application Repository" that supposedly enables the deployment of SSO Sync doesn't work.

    There's actually an open issue that many people aren't able to access it and the reason seems to be that the related account was deleted. 3. Following the manual instructions just doesn't work, there are multiple bugs.

    From the workshop link you provided it's also stated in the intro that - "AWS Single Sign-On (SSO) currently does not support Google Workspace as an identity provider for automatic provisioning of users and groups, or the ssosync application, available on the AWS Serverless Application Repository."

