Difference between revisions of "Set up Google Workspace SSO via SAML for Amazon Web Services"

From wikieduonline
Jump to navigation Jump to search
 
(7 intermediate revisions by the same user not shown)
Line 1: Line 1:
 
+
*  https://support.google.com/a/answer/6194963
  
  
Line 5: Line 5:
 
* [[Google Workspace]]: https://support.google.com/a/answer/6194963
 
* [[Google Workspace]]: https://support.google.com/a/answer/6194963
  
 
+
Step 1 should be ...
Should be
+
:<code>Step 1 Security -> Authentication -> SSO with Google as SAML IdP</code>
:Step 1 Security -> Authentication -> SSO with Google as SAML IdP
 
 
instead of...
 
instead of...
:Step 1 Security -> Set up single sign-on (SSO) for SAML applications.
+
:<code>Step 1 Security -> Set up single sign-on (SSO) for SAML applications.</code>
  
 +
Step 2 should be ...
 +
: ?.../...
 +
instead of ...
 +
:<code>On the Select Role Type page, under Role for Identity Provider Access, select Grant Web Single Sign-On (WebSSO) access to SAML providers.</code>
  
 
Misc: [[SSO URL]], [[Entity ID]], [[IdP metadata]]
 
Misc: [[SSO URL]], [[Entity ID]], [[IdP metadata]]
Line 18: Line 21:
 
:https://aws.amazon.com/SAML/Attributes/RoleSessionName
 
:https://aws.amazon.com/SAML/Attributes/RoleSessionName
 
:https://aws.amazon.com/SAML/Attributes/Role
 
:https://aws.amazon.com/SAML/Attributes/Role
 +
* AWS documentation (Jul 2020) [[How to use G Suite as an external identity provider for AWS SSO]] https://aws.amazon.com/blogs/security/how-to-use-g-suite-as-external-identity-provider-aws-sso/
 
* [[Google Workspace]]: https://support.google.com/a/answer/6194963
 
* [[Google Workspace]]: https://support.google.com/a/answer/6194963
  
Line 23: Line 27:
 
* [[AWS Role]]: Create a [[role]] for [[SAML]] federation https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_create_for-idp_saml.html
 
* [[AWS Role]]: Create a [[role]] for [[SAML]] federation https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_create_for-idp_saml.html
 
* <code>[[SAMLResponse]]</code>: <code>[[Your request included an invalid saml response]]</code>
 
* <code>[[SAMLResponse]]</code>: <code>[[Your request included an invalid saml response]]</code>
 +
* [[How to set up IAM federation using Google Workspace]]
  
 
== See also ==
 
== See also ==

Latest revision as of 07:18, 17 March 2022


Google doc[edit]

Step 1 should be ...

Step 1 Security -> Authentication -> SSO with Google as SAML IdP

instead of...

Step 1 Security -> Set up single sign-on (SSO) for SAML applications.

Step 2 should be ...

 ?.../...

instead of ...

On the Select Role Type page, under Role for Identity Provider Access, select Grant Web Single Sign-On (WebSSO) access to SAML providers.

Misc: SSO URL, Entity ID, IdP metadata

Related documentation[edit]

https://aws.amazon.com/SAML/Attributes/RoleSessionName
https://aws.amazon.com/SAML/Attributes/Role

Related[edit]

See also[edit]

Advertising: