Accessing IAM Identity Center

2

Good Morning,

I created an app with Amazon Q and I wish to deploy it (Deploy web experience). Unfortunately I can't enable IAM identity Center (IAM Identity Center is already set up with an organization instance).

How can I access it ? What permissions should I need for my account ?

Best regards,

2 個答案
2

Hello,

Confirm the IAM role passed to Amazon Q during deployment has the necessary permissions for the QBusiness actions like Chat, ListMessages, etc. as described in the documentation -

https://docs.aws.amazon.com/amazonq/latest/business-use-dg/idp-sso.html https://docs.aws.amazon.com/amazonq/latest/aws-builder-use-ug/setting-up-configure-permissions.html https://docs.aws.amazon.com/amazonq/latest/business-use-dg/iam-roles.html

  • Verify the trust relationship is set up correctly between Identity Center and Amazon Q by checking the SAML metadata exchange completed successfully.
  • Ensure the IAM user or role you're using to access the web experience is a member of the appropriate group in the Identity Center that was configured during deployment.
  • For the IAM user or role, attach the AmazonQFullAccess managed policy for full permissions to Amazon Q.
  • Double-check the email attribute and optional group attribute names match what's configured in the Identity Center and passed to Amazon Q.

Thanks

Abhinav

已回答 4 個月前
  • hum, the web preview works fine. To deploy I would need to access the IAM Identity Center. Should I had AWSIAMIdentityCenterAllowListForIdentityContext permission to my account ?

0

hum, the web preview works fine. To deploy I would need to access the IAM Identity Center. Should I had AWSIAMIdentityCenterAllowListForIdentityContext permission to my account ?

已回答 4 個月前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南