SSO with AWS Managed Microsoft AD Directory Service - Something went wrong

0

Hi, I'm new to AWS so please be gentle with me.

Everything mentioned here is in the same region: I've setup Organisations and have a few sub accounts. An AWS Managed Microsoft Active Directory, Directory Service has been setup and AWS SSO has been enabled with the Identity Provider changed over to be the MS AD. A permission set has been created using the AdministratorAccess job function policy. This policy has been linked to each AWS account through the IAM Identity Center using an AD Group, linked to the Permission set created.

When I visit the SSO login page, I can see that the user account has been granted AdministratorAccess to the accounts where it has been linked. However, when the Management Console link is selected for any of the accounts a red banner appears at the top right of the page with the words: "Oops, something went wrong, Provide your administrator with the following info: No Access." There is also a HTTP status code of 403 which suggests that permissions have not been set correctly.

I have seen a few YT videos which walk through this process, using MS AD as the identity provider and it all just seems to work for them without any complication. I've also seen some AWS documentation which suggests that there needs to be configuration around the Directory Service and IAM to allow users to be assigned access to the Management Console there.

Any help with understanding what's wrong here would be great. A better error message wouldn't be a bad thing as searching for the above hasn't led me to any hints as to what's wrong.

Hugo
已提問 1 年前檢視次數 600 次
1 個回答
1
已接受的答案

Hi There

Have you changed anything as far as attribute mappings or the email field in AD? Take a look at this previous post https://repost.aws/questions/QUAqB5ERupRE2GY9RcUSA2zQ/problem-with-sso

profile pictureAWS
專家
Matt-B
已回答 1 年前
  • Thank you so much for answering my question, that's had me around the bend for a day or so now. It's a shame that the error isn't more specific and that the documentation that I've seen doesn't mention that an email address in the AD account as a requirement.

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南