RDS Postgres can be configured to connect to an AWS Managed Active Directory for user authentication. The AWS Managed Active Directory can then be connected to an on-premises AD through a forest trust.
This will allow you to authenticate users from either directory.
The following two links explains how to set this up. https://aws.amazon.com/about-aws/whats-new/2019/10/amazon-rds-for-postgresql-supports-user-authentication-with-kerberos-and-microsoft-active-directory/ https://docs.aws.amazon.com/quickstart/latest/active-directory-ds/scenario-2.html
This step is the bulk of the work: https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/postgresql-kerberos-setting-up.html
The way RDS Postgres manages users is that a local Postgres database user will still need to be created to match the AD account for every user that needs access. I don't believe its possible to do this for an AD group and have all users in the group just work
Therefore, just because the RDS instance is using kerberos to AD, it doesn't automatically give users access.
Note that the capitalization of the domain is essential. It must be in CAPITALS. The username is also case sensitive and must match the username in AD (windows ignores the case so you might not be aware of any capitalization in user names)
AWS SSO with Microsoft AD as IdPasked 8 months ago
How to restrict database users for RDS Postgres using AWS Managed AD trusted with customer on-prem ADAccepted Answerasked 2 years ago
AWS MANAGED MICROSOFT ADasked 5 months ago
Joining an AWS Managed Microsoft AD to an existing domainAccepted Answerasked 2 years ago
Can Redshift authenticate to AWS Managed AD and how?Accepted Answerasked 2 years ago
Find old Forum Thread ID for migrating our Simple AD to a new AWS Managed Microsoft ADasked 6 months ago
Amazon Workspaces without AD connectorAccepted Answerasked 3 years ago
JIT SAML Attributes when using Managed AD with AWS SSOasked 11 days ago
Can we extend OnPrem to Managed AD with trust then do migration with ADMTAccepted Answerasked a year ago
Is there a way to migrate directory services from Simple AD to AWS Managed Microsoft AD?asked 2 months ago