AWS SSO with Google SAML group mapping

2

Hello guys. Can anyone help me with Google group mapping configured via SAML for SSO

Google and Amazon announces a new feature - automatic provisioning:

https://support.google.com/a/answer/6194963?hl=en#zippy=%2Cstep-set-up-google-as-a-saml-identity-provider-idp https://aws.amazon.com/about-aws/whats-new/2023/06/aws-iam-identity-center-automated-user-provisioning-google-workspace/

I've tested it and, yes it works. I'm able to sync my Users in Google Directory to AWS Users in Identity Center via SAML. Thanks a lot for this feature!!! But, unfortunately, group mapping between Google and AWS still doesn't work. The idea is to sync User group membership in Google Directory with groups in AWS Identity Center. In google SAML attribute mapping there is settings "Group membership (optional)" where I can choose my Google groups, but I can't understand what attributes I need to substitute into field "App attribute" in order for me to have a mapping between groups In Google and AWS. I have no idea how it should be configured on AWS side. I read a bunch of documents, tried different options with mapping observing all possible attribute parameters in SAML schema of data and SCIM settings, tried create custom attributes on AWS and Google SAML connector side, but none of the options works. Is it work actually? Enter image description here

Enter image description here

1 Answer
0

The Federation currently support only user provisioning. You can read up here. Please read the blue box "Note" section.

AWS
answered 9 months ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions