79554846

Date: 2025-04-04 08:39:46
Score: 1.5
Natty:
Report link

I first tried with IAM Identity Center which didnt work as we have a Parent account ( Management Account heirarchy) which will force us to have all the child accounts including ours to be onboarded with OKta

That's kind of the point of IAM Identity Center - a centralised federation point that allows you to easily federate all accounts in an AWS Organization with your centralised IdP. Are you sure that this isn't what you want?

Even through the integration I was confused as it didnt had any steps where users are created in AWS

You don't create IAM Users when using SAML federation, you create IAM Roles. You then map your human identities to IAM Roles in your IdP, allowing users to assume those roles in AWS with temporary credentials.

Have you tried viewing the SAML response to see if there is an obvious error?

Reasons:
  • Whitelisted phrase (-1): Have you tried
  • Long answer (-0.5):
  • No code block (0.5):
  • Ends in question mark (2):
  • Low reputation (0.5):
Posted by: andycaine