How to Configure SAML Authentication for AWS IAM Identity Center (formerly AWS Single Sign-On)

Note: Advance configuration on the AWS side is required.
Note: In July 2022, AWS IAM Identity Center was renamed from AWS Single Sign-On. The configuration steps are almost unchanged, but please note that the names and screenshots in this manual are from AWS SSO, so the actual screens may differ.
Note: For the latest configuration steps, please refer to the manual provided by Amazon.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "AWS Single Sign-On (SAML)."
    02.png

  3. Download the metadata from "Download Metadata" under "Identity Provider Information."
    03.png

Now, let's move on to the settings on the AWS side.
Without clicking the "Register" button, open the AWS Single Sign-On Console in a separate tab.

AWS Settings

  1. AWS Single Sign-On Console and sign in.

  2. Select "Enable AWS SSO." Note: This can only be enabled by a root account.
    04.png

  3. Confirm that it has been enabled successfully.
    05.png

  4. From "Settings," select "Actions > Change identity source."
    06.png

  5. Select "External ID provider."
    07.png

  6. Download the metadata from "Download metadata file" under "Service provider metadata." You will upload this downloaded metadata file to TrustLogin later.
    08.png

  7. Upload the metadata you downloaded from TrustLogin to "IdP SAML metadata," then click "Next."

    09.png

  8. Enter "Accept" and select "Change identity source."
    10.png

  9. Confirm that the message is displayed.
    11.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Upload the metadata file obtained from AWS via "Select Metadata" on the app registration screen.
    12.png

  2. Click the "Register" button to save.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page."
  2. On the "Register App" screen, select "AWS Single Sign-On (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an administrator adds a member

  1. Search for the "AWS Single Sign-On (SAML)" app in the "Admin Page > Apps" menu and click it.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.

Adding a User in AWS

  1. Register the user on the AWS side. Select "Add users" from "Users."
    13.png

  2. Enter the information for the user you registered to the app in TrustLogin, then click "Next."
    14.png

  3. Since no particular configuration is needed this time, simply select "Next" to proceed.
    15.png

  4. Click "Add user" and confirm that the user has been added successfully.
    16.png
    16-2.png

  5. Open "Permission sets" and click "Create permission set."
    17.png

  6. Set the permission set type to "Predefined permission set," select "AdministratorAccess" from the list of AWS managed policies below, and proceed with "Next."
    18.png

  7. Set a permission set name of your choice and proceed with "Next."
    19.png

  8. Review the details and click "Create."
    20.png

  9. Confirm that the permission set has been created.
    21.png

  10. Open "AWS accounts" and click the account name link.
    24.png

  11. Select "Assign users or groups."
    25.png

  12. Check the box for the user you created earlier and click "Next."
    26.png

  13. Check the box for the permission set you created earlier and click "Next."
    27.png

  14. Review the details and click "Submit."
    28.png

  15. Confirm that the permission set has been applied to the account.
    29.png

Verifying the Connection

  1. Find the user portal URL from the AWS SSO dashboard and click it.
    30.png

  2. You will be redirected to the TrustLogin sign-in page, so log in there.
    30.png

  3. You will be redirected to the AWS screen.
    31.png

  4. Click "AWS Account" to display the account name, and expand it further to display the assigned permission set. Select "Management Console" to its right.
    32.png

  5. The AWS Management Console will be displayed.
    33.png

How to Configure SAML Authentication for AWS IAM Identity Center (formerly AWS Single Sign-On)

Note: Advance configuration on the AWS side is required.
Note: In July 2022, AWS IAM Identity Center was renamed from AWS Single Sign-On. The configuration steps are almost unchanged, but please note that the names and screenshots in this manual are from AWS SSO, so the actual screens may differ.
Note: For the latest configuration steps, please refer to the manual provided by Amazon.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "AWS Single Sign-On (SAML)."
    02.png

  3. Download the metadata from "Download Metadata" under "Identity Provider Information."
    03.png

Now, let's move on to the settings on the AWS side.
Without clicking the "Register" button, open the AWS Single Sign-On Console in a separate tab.

AWS Settings

  1. AWS Single Sign-On Console and sign in.

  2. Select "Enable AWS SSO." Note: This can only be enabled by a root account.
    04.png

  3. Confirm that it has been enabled successfully.
    05.png

  4. From "Settings," select "Actions > Change identity source."
    06.png

  5. Select "External ID provider."
    07.png

  6. Download the metadata from "Download metadata file" under "Service provider metadata." You will upload this downloaded metadata file to TrustLogin later.
    08.png

  7. Upload the metadata you downloaded from TrustLogin to "IdP SAML metadata," then click "Next."

    09.png

  8. Enter "Accept" and select "Change identity source."
    10.png

  9. Confirm that the message is displayed.
    11.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Upload the metadata file obtained from AWS via "Select Metadata" on the app registration screen.
    12.png

  2. Click the "Register" button to save.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page."
  2. On the "Register App" screen, select "AWS Single Sign-On (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an administrator adds a member

  1. Search for the "AWS Single Sign-On (SAML)" app in the "Admin Page > Apps" menu and click it.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.

Adding a User in AWS

  1. Register the user on the AWS side. Select "Add users" from "Users."
    13.png

  2. Enter the information for the user you registered to the app in TrustLogin, then click "Next."
    14.png

  3. Since no particular configuration is needed this time, simply select "Next" to proceed.
    15.png

  4. Click "Add user" and confirm that the user has been added successfully.
    16.png
    16-2.png

  5. Open "Permission sets" and click "Create permission set."
    17.png

  6. Set the permission set type to "Predefined permission set," select "AdministratorAccess" from the list of AWS managed policies below, and proceed with "Next."
    18.png

  7. Set a permission set name of your choice and proceed with "Next."
    19.png

  8. Review the details and click "Create."
    20.png

  9. Confirm that the permission set has been created.
    21.png

  10. Open "AWS accounts" and click the account name link.
    24.png

  11. Select "Assign users or groups."
    25.png

  12. Check the box for the user you created earlier and click "Next."
    26.png

  13. Check the box for the permission set you created earlier and click "Next."
    27.png

  14. Review the details and click "Submit."
    28.png

  15. Confirm that the permission set has been applied to the account.
    29.png

Verifying the Connection

  1. Find the user portal URL from the AWS SSO dashboard and click it.
    30.png

  2. You will be redirected to the TrustLogin sign-in page, so log in there.
    30.png

  3. You will be redirected to the AWS screen.
    31.png

  4. Click "AWS Account" to display the account name, and expand it further to display the assigned permission set. Select "Management Console" to its right.
    32.png

  5. The AWS Management Console will be displayed.
    33.png