I know it's 6 years late, but it's possible now to authenticate the user if they already reside in AWS as an IAM user. Check this official tutorial by the Amazon Web Services channel on youtube.