QuickSight access for federated user/role

0

Dear experts,

is there a way to provide access to QuickSight for a federated user? I am not sure, whether my question is precise and I could re-add details later, if needed. In any case I am talking about access to aws I reveived via

Your AD User ... with primary email address ... has been authorized for the following IAM roles: • fpc/UserFull in <account ID>: https://signin.aws.amazon.com/switchrole?account=<account ID>&roleName=fpc/UserFull

Thanks in advance!

Thomas

1 Answer
0
Accepted Answer

Yes, it is possible to provide access to Amazon QuickSight for federated users. There are a few different approaches you can take:

Configure QuickSight access through an external identity provider (IdP) like Active Directory, and IAM. QuickSight will link to the user record in the IdP. You can assign QuickSight permissions like admin, author or reader based on IdP group memberships.

Configure QuickSight access through AWS SSO (successor to AWS Single Sign-On). You can follow the documentation to set up the IdP connection between AWS SSO and QuickSight to enable federated authentication.

For the Enterprise edition of QuickSight, you can also directly connect QuickSight to an Active Directory. The user passwords will be managed in Active Directory, and users log in through the QuickSight console.

In all the cases, federated users will get single sign-on access to QuickSight without needing separate IAM users or local QuickSight users to be created. You can use IAM policies to control the level of self-service access federated users have for provisioning QuickSight.

profile picture
EXPERT
answered 3 months ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions