Unable to use AD groups after enabling Configurable AD Sync in SSO

0

We are using AWS SSO with AWS Managed Microsoft AD as source for quite some time. There was a notification toe enable "Configurable AD Sync" and we enabled it today. Per the information on the AD Sync page, all the existing user and group assignment should not be affected after the change.

We see the permissions assigned to individual users are unaffected. But the permission sets assigned to the AD groups are no longer working. When I try to change the permission set of an AD group, I get "Unexpected error Received a 404 status error: null".

Also, there are 15 groups shown in AWS SSO > Settings > Manage sync > Groups. But on the assign permission set page, there is only one group available. We are not sure if there is any step missing in this configuration. Could someone please point us towards the correct direction?

已提問 2 年前檢視次數 660 次
1 個回答
0
已接受的答案

We created a support ticket with AWS and they informed us that the groups will not sync if the group description has any of these four special characters <>;:

After removing the special characters from our AD groups and waiting for the groups to sync, we are able to see the groups again in AWS SSO.

已回答 2 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南