Initial Setup Steps for Identity Provisioning with AWS

This page describes the initial setup steps for using TrustLogin as the source of identity
to perform Identity Provisioning to AWS.

Note: For detailed instructions on operating AWS, please refer to the manual provided by AWS.

Item

Details

Pre-check

  • You must be able to log in to the AWS Management Console.
  • You must be able to perform operations in IAM Identity Center.

Setup Flow / Manual

Note: After connecting TrustLogin and AWS using the steps on this page,
 please proceed to user synchronization settings.

Provisioning Target

Supports user provisioning

Supports group provisioning

SAML Authentication Setup Manual

How to Configure SAML Authentication for AWS IAM Identity Center (formerly AWS Single Sign-On)
 

  • The Identity Provisioning configuration created in this procedure can be linked to an existing SAML app.
    For details on the SAML app configuration, please see here.

Notes

  • None in particular

 

Setup Steps

AWS Settings

  1. Log in to the AWS Management Console, and enter "IAM" in the search field.
    AWS_IDProv_01.png
     
  2. Click "IAM Identity Center". 
    AWS_IDProv_02.png
     
  3. Click "Settings" on the left side of the screen.
    AWS_IDProv_03.png
     
  4. From the "Actions" dropdown for the identity source, select "Manage provisioning".
    AWS_IDProv_04.png
     
  5. Copy the "SCIM endpoint". (This will be used in the TrustLogin settings.)
    AWS_IDProv_05.png
     
  6. Click "Generate token".
    AWS_IDProv_06.png
     
  7. Copy the "Access token".
    AWS_IDProv_07.png
     

  8. The token has been registered.
    This completes the preparation on the AWS side. Next, configure the settings on the TrustLogin side.
    AWS_IDProv_08.png
     

     

TrustLogin Settings

  1. Log in to the TrustLogin Admin Page, and from the "Admin Page > Settings > Optional Features" menu,
    open "Settings" next to "Identity Provisioning".
    IDProvServiceCommon01.png
     

  2. Click "Add Service".
    IDProvServiceCommon02.png
     
     
  3. Search for "AWS", select it, and click the "Add" button.
    AWS_IDProv_09.png
     
  4. You will be redirected to the "Identity Provisioning > AWS" page.
    Click the "Edit" button.
    AWS_IDProv_10.png
     
  5. Open "Access Settings", enter the following values for each setting item, and click "Save".

    Connection URL The "SCIM endpoint" copied in step 5 of AWS Settings
    Access Token The "Access token" copied in step 7 of AWS Settings

    AWS_IDProv_11.png
     

  6. Click the "Connect" button. 
    AWS_IDProv_12.png
     
  7. Once the button status updates to "Connected", the initial setup is complete.
    AWS_IDProv_13.png
     

Next step: The manual for configuring user synchronization is available here

 

Values You Can Configure in Attribute Mapping

The values that can be specified as default functions for AWS are as follows.

Value Description

Full Name

This is the full name with the surname first.

Full Name (Given Name First)

This is the full name with the given name first.

Username from Email

Retrieves the portion of the email address before the "@" and limits it to a maximum of 21 characters.

Phone Number

Standardizes the phone number into the format xx-xxxx-xxxx or xxx-xxxx-xxxx.

Postal Code

Standardizes the postal code into the format xxx-xxxx.

Note: For an overview of the attribute mapping feature and how to configure it, please see here.

 


 

 

 

 

 

 

 

 

 

 

Initial Setup Steps for Identity Provisioning with AWS

This page describes the initial setup steps for using TrustLogin as the source of identity
to perform Identity Provisioning to AWS.

Note: For detailed instructions on operating AWS, please refer to the manual provided by AWS.

Item

Details

Pre-check

  • You must be able to log in to the AWS Management Console.
  • You must be able to perform operations in IAM Identity Center.

Setup Flow / Manual

Note: After connecting TrustLogin and AWS using the steps on this page,
 please proceed to user synchronization settings.

Provisioning Target

Supports user provisioning

Supports group provisioning

SAML Authentication Setup Manual

How to Configure SAML Authentication for AWS IAM Identity Center (formerly AWS Single Sign-On)
 

  • The Identity Provisioning configuration created in this procedure can be linked to an existing SAML app.
    For details on the SAML app configuration, please see here.

Notes

  • None in particular

 

Setup Steps

AWS Settings

  1. Log in to the AWS Management Console, and enter "IAM" in the search field.
    AWS_IDProv_01.png
     
  2. Click "IAM Identity Center". 
    AWS_IDProv_02.png
     
  3. Click "Settings" on the left side of the screen.
    AWS_IDProv_03.png
     
  4. From the "Actions" dropdown for the identity source, select "Manage provisioning".
    AWS_IDProv_04.png
     
  5. Copy the "SCIM endpoint". (This will be used in the TrustLogin settings.)
    AWS_IDProv_05.png
     
  6. Click "Generate token".
    AWS_IDProv_06.png
     
  7. Copy the "Access token".
    AWS_IDProv_07.png
     

  8. The token has been registered.
    This completes the preparation on the AWS side. Next, configure the settings on the TrustLogin side.
    AWS_IDProv_08.png
     

     

TrustLogin Settings

  1. Log in to the TrustLogin Admin Page, and from the "Admin Page > Settings > Optional Features" menu,
    open "Settings" next to "Identity Provisioning".
    IDProvServiceCommon01.png
     

  2. Click "Add Service".
    IDProvServiceCommon02.png
     
     
  3. Search for "AWS", select it, and click the "Add" button.
    AWS_IDProv_09.png
     
  4. You will be redirected to the "Identity Provisioning > AWS" page.
    Click the "Edit" button.
    AWS_IDProv_10.png
     
  5. Open "Access Settings", enter the following values for each setting item, and click "Save".

    Connection URL The "SCIM endpoint" copied in step 5 of AWS Settings
    Access Token The "Access token" copied in step 7 of AWS Settings

    AWS_IDProv_11.png
     

  6. Click the "Connect" button. 
    AWS_IDProv_12.png
     
  7. Once the button status updates to "Connected", the initial setup is complete.
    AWS_IDProv_13.png
     

Next step: The manual for configuring user synchronization is available here

 

Values You Can Configure in Attribute Mapping

The values that can be specified as default functions for AWS are as follows.

Value Description

Full Name

This is the full name with the surname first.

Full Name (Given Name First)

This is the full name with the given name first.

Username from Email

Retrieves the portion of the email address before the "@" and limits it to a maximum of 21 characters.

Phone Number

Standardizes the phone number into the format xx-xxxx-xxxx or xxx-xxxx-xxxx.

Postal Code

Standardizes the postal code into the format xxx-xxxx.

Note: For an overview of the attribute mapping feature and how to configure it, please see here.