How to Configure SAML Authentication for AWS IAM

Note: You must create an account in AWS using the same email address as your TrustLogin (formerly SKUID) account.
Note: Depending on the AWS service, unique SAML authentication specifications may be required. For details, please refer to the manual for each AWS service.

Note: For the latest configuration steps, please refer to the manual provided by AWS.

  

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.

    aws_01.png

  2. Search on the "Register Corporate App" screen and select "AWS IAM (SAML)."

    aws_02.png

  3. Download the metadata from "Download Metadata" under "Identity Provider Information."

    aws_03.png

Now, let's move on to the settings on the AWS side.
Without clicking the "Register" button, open the AWS Management Console in a separate window.

AWS Settings

  1. Search for "IAM" in the service search bar to open the IAM management screen.

    aws_04.png

  2. [Create an Identity Provider]
    Reference: Creating an IAM SAML identity provider

    Open "Identity providers" in the left menu and click "Add provider."

    aws_05.png

  3. Select "SAML" from the "Select provider type" dropdown and proceed with "Next Step" in the lower right.

    aws_06.png

  4. Enter a "Provider Name" and upload the metadata downloaded from TrustLogin to "Metadata Document."
    (The "Provider Name" can be anything you like. Here, we use TrustLogin as an example.)
    Proceed with "Next Step" in the lower right.

    aws_07.png

  5. Click "Create" in the lower right.

    aws_08.png

  6. Select the provider you created to open it.

    aws_09.png

  7. Make a note of the "Provider ARN."

    aws_10.png

  8. [Create a Role]
    Reference: Creating a role for SAML 2.0 federation (console) 

    Open "Roles" in the left menu and click "Create role."

    aws_11.png

  9. Select "SAML 2.0 federation" and configure each of the fields displayed below as follows.

    SAML provider

    Select the provider you created earlier.
    Attribute

    SAML:aud

    Value https://signin.aws.amazon.com/saml

    Proceed with "Next: Permissions."

    aws_12.png

  10. Select a policy according to the service you plan to use, and proceed with "Next: Tags."

    aws_13.png

  11. Proceed with "Next: Review" as is.

    aws_14.png

  12. Enter a "Role name" (any name you like) and click "Create role."

    aws_15.png

  13. Select the role you created to open it.

    aws_16.png

  14. Make a note of the "Role ARN."

    aws_17.png

Return to the TrustLogin settings page again.

TrustLogin Admin Page Settings (Continued)

  1. In the "SAML Attribute Settings" section of "Service Provider Settings," enter the "Role ARN" and "Provider ARN" you noted down from AWS in the field outlined in red below, separated by a comma, in the format "Role ARN,Provider ARN."
    aws_19.png

    You can leave the "Redirect URL After Successful SP Authentication" field blank.

    aws_18.png

  2. Click the "Register" button to save.

    aws_20.png

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page."
  2. On the "Register App" screen, select "AWS IAM (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an administrator adds a member

  1. Search for the "AWS IAM (SAML)" app in the "Admin Page > Apps" menu and click it.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for AWS IAM

Note: You must create an account in AWS using the same email address as your TrustLogin (formerly SKUID) account.
Note: Depending on the AWS service, unique SAML authentication specifications may be required. For details, please refer to the manual for each AWS service.

Note: For the latest configuration steps, please refer to the manual provided by AWS.

  

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.

    aws_01.png

  2. Search on the "Register Corporate App" screen and select "AWS IAM (SAML)."

    aws_02.png

  3. Download the metadata from "Download Metadata" under "Identity Provider Information."

    aws_03.png

Now, let's move on to the settings on the AWS side.
Without clicking the "Register" button, open the AWS Management Console in a separate window.

AWS Settings

  1. Search for "IAM" in the service search bar to open the IAM management screen.

    aws_04.png

  2. [Create an Identity Provider]
    Reference: Creating an IAM SAML identity provider

    Open "Identity providers" in the left menu and click "Add provider."

    aws_05.png

  3. Select "SAML" from the "Select provider type" dropdown and proceed with "Next Step" in the lower right.

    aws_06.png

  4. Enter a "Provider Name" and upload the metadata downloaded from TrustLogin to "Metadata Document."
    (The "Provider Name" can be anything you like. Here, we use TrustLogin as an example.)
    Proceed with "Next Step" in the lower right.

    aws_07.png

  5. Click "Create" in the lower right.

    aws_08.png

  6. Select the provider you created to open it.

    aws_09.png

  7. Make a note of the "Provider ARN."

    aws_10.png

  8. [Create a Role]
    Reference: Creating a role for SAML 2.0 federation (console) 

    Open "Roles" in the left menu and click "Create role."

    aws_11.png

  9. Select "SAML 2.0 federation" and configure each of the fields displayed below as follows.

    SAML provider

    Select the provider you created earlier.
    Attribute

    SAML:aud

    Value https://signin.aws.amazon.com/saml

    Proceed with "Next: Permissions."

    aws_12.png

  10. Select a policy according to the service you plan to use, and proceed with "Next: Tags."

    aws_13.png

  11. Proceed with "Next: Review" as is.

    aws_14.png

  12. Enter a "Role name" (any name you like) and click "Create role."

    aws_15.png

  13. Select the role you created to open it.

    aws_16.png

  14. Make a note of the "Role ARN."

    aws_17.png

Return to the TrustLogin settings page again.

TrustLogin Admin Page Settings (Continued)

  1. In the "SAML Attribute Settings" section of "Service Provider Settings," enter the "Role ARN" and "Provider ARN" you noted down from AWS in the field outlined in red below, separated by a comma, in the format "Role ARN,Provider ARN."
    aws_19.png

    You can leave the "Redirect URL After Successful SP Authentication" field blank.

    aws_18.png

  2. Click the "Register" button to save.

    aws_20.png

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page."
  2. On the "Register App" screen, select "AWS IAM (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an administrator adds a member

  1. Search for the "AWS IAM (SAML)" app in the "Admin Page > Apps" menu and click it.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.