This page describes the initial setup steps for using TrustLogin as the source of identity
to perform Identity Provisioning to AWS.
Note: For detailed instructions on operating AWS, please refer to the manual provided by AWS.
Item |
Details |
|
Pre-check |
|
|
Setup Flow / Manual |
Note: After connecting TrustLogin and AWS using the steps on this page, |
|
Provisioning Target |
〇 |
Supports user provisioning |
〇 |
Supports group provisioning | |
SAML Authentication Setup Manual |
How to Configure SAML Authentication for AWS IAM Identity Center (formerly AWS Single Sign-On)
|
|
Notes |
|
|
Setup Steps
AWS Settings
- Log in to the AWS Management Console, and enter "IAM" in the search field.
- Click "IAM Identity Center".
- Click "Settings" on the left side of the screen.
- From the "Actions" dropdown for the identity source, select "Manage provisioning".
- Copy the "SCIM endpoint". (This will be used in the TrustLogin settings.)
- Click "Generate token".
Copy the "Access token".
- The token has been registered.
This completes the preparation on the AWS side. Next, configure the settings on the TrustLogin side.
TrustLogin Settings
Log in to the TrustLogin Admin Page, and from the "Admin Page > Settings > Optional Features" menu,
open "Settings" next to "Identity Provisioning".
- Click "Add Service".
- Search for "AWS", select it, and click the "Add" button.
- You will be redirected to the "Identity Provisioning > AWS" page.
Click the "Edit" button.
-
Open "Access Settings", enter the following values for each setting item, and click "Save".
Connection URL The "SCIM endpoint" copied in step 5 of AWS Settings Access Token The "Access token" copied in step 7 of AWS Settings
- Click the "Connect" button.
Once the button status updates to "Connected", the initial setup is complete.
Next step: The manual for configuring user synchronization is available here
Values You Can Configure in Attribute Mapping
The values that can be specified as default functions for AWS are as follows.
| Value | Description |
Full Name |
This is the full name with the surname first. |
Full Name (Given Name First) |
This is the full name with the given name first. |
Username from Email |
Retrieves the portion of the email address before the "@" and limits it to a maximum of 21 characters. |
Phone Number |
Standardizes the phone number into the format xx-xxxx-xxxx or xxx-xxxx-xxxx. |
Postal Code |
Standardizes the postal code into the format xxx-xxxx. |
Note: For an overview of the attribute mapping feature and how to configure it, please see here.