SSO with AWS Managed Microsoft AD Directory Service - Something went wrong

0

Hi, I'm new to AWS so please be gentle with me.

Everything mentioned here is in the same region: I've setup Organisations and have a few sub accounts. An AWS Managed Microsoft Active Directory, Directory Service has been setup and AWS SSO has been enabled with the Identity Provider changed over to be the MS AD. A permission set has been created using the AdministratorAccess job function policy. This policy has been linked to each AWS account through the IAM Identity Center using an AD Group, linked to the Permission set created.

When I visit the SSO login page, I can see that the user account has been granted AdministratorAccess to the accounts where it has been linked. However, when the Management Console link is selected for any of the accounts a red banner appears at the top right of the page with the words: "Oops, something went wrong, Provide your administrator with the following info: No Access." There is also a HTTP status code of 403 which suggests that permissions have not been set correctly.

I have seen a few YT videos which walk through this process, using MS AD as the identity provider and it all just seems to work for them without any complication. I've also seen some AWS documentation which suggests that there needs to be configuration around the Directory Service and IAM to allow users to be assigned access to the Management Console there.

Any help with understanding what's wrong here would be great. A better error message wouldn't be a bad thing as searching for the above hasn't led me to any hints as to what's wrong.

Hugo
已提问 1 年前600 查看次数
1 回答
1
已接受的回答

Hi There

Have you changed anything as far as attribute mappings or the email field in AD? Take a look at this previous post https://repost.aws/questions/QUAqB5ERupRE2GY9RcUSA2zQ/problem-with-sso

profile pictureAWS
专家
Matt-B
已回答 1 年前
  • Thank you so much for answering my question, that's had me around the bend for a day or so now. It's a shame that the error isn't more specific and that the documentation that I've seen doesn't mention that an email address in the AD account as a requirement.

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则