Skip to content

Migrating workloads from one AWS account to another

0

I want a seamless Cognito User Pool migration between AWS accounts, where users don’t have to reset passwords or re-register. Since Cognito does not natively support direct user export/import with passwords due to security design. Is there any best way to do with minimum downtime ?

1 Answer
0

See whether this can help:

  1. Create a New User Pool in the Destination Account • Enable User Migration Lambda Trigger. • Ensure the new pool supports the same attributes and authentication flow (e.g., USER_PASSWORD_AUTH).
  2. Set Up a Lambda Function

o Authenticate the user against the old user pool. o Return user attributes to the new pool. o Create the user in the new pool without requiring password reset.

  1. Configure IAM Roles for Cross-Account Access • In the old account, create a role that allows: o cognito-idp:AdminInitiateAuth o cognito-idp:AdminGetUser o cognito-idp:ListUsers • Trust the Lambda execution role from the new account.
  2. Attach the Lambda to the New User Pool • Go to User Pool > Triggers > Migration. • Select your Lambda function.
EXPERT

answered 9 months ago

AWS
EXPERT

reviewed 9 months ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.