issues with AWS SSO linking to Google Workspaces

0

After following this tutorial step by step https://aws.amazon.com/blogs/security/how-to-use-g-suite-as-external-identity-provider-aws-sso/ I get a 403 error every time

  1. That’s an error. Error: app_not_configured_for_user Service is not configured for this user.

I double checked every field and Identity especially and nothing seems to point where the issue is coming from.

Any tips for debugging?

已提问 2 年前3149 查看次数
4 回答
1
已接受的回答

Sorry for answering this myself. While the other answers are indeed correct my issue was totally unrelated and was most likely to the work google workspaces works. After 24 hours from setting up the connection it started working by itself. Writing this just in case others run into this issue. If you are 100% sure you set everything according to the article and still get the error, have some patience, it will work.

已回答 2 年前
0

Based on the error prompt & as per my understanding, this points out the need for additional settings on the Google Apps account. Can you verify that the value in the saml:Issuer tag in the SAMLRequest matches the Entity ID value configured in the SAML Service Provider Details section in the Admin console. This value is case-sensitive.

profile pictureAWS
支持工程师
已回答 2 年前
  • Well the entities and other values were transferred via the IdP file as in the tutorial and was values are all lowercase. Is there any way to actually check the SAML Request?

0

I've set this up recently and have seen that error. From what I understand it means the user you are logged in with\ trying to log in with does not have access to the SAML app you configured in Google Workspaces. From experience this can happen because you are already logged into a different Google account that does not have access or you have not configured your SAML app in Google Workspaces to allow the user have you logged in with access to it.

In the blog post under step 7 it directs you to "select ON for everyone", have you done that? Or otherwise have you configured an Organizational Unit or Group to have access that your user is not part of?

已回答 2 年前
0

The trick is to make the Google account you want to use with AWS your default Google account. You do that by clicking "Sign out of all accounts" in Google, and then, first login to the account you want to use as the default account, and then login with your secondary accounts.

Benoit
已回答 4 天前

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则