For the complete documentation index, see llms.txt. This page is also available as Markdown.

Federated

Configure the P0 AWS IAM management integration to provision users through an Okta SAML federation, granting IAM roles assigned to your AWS Account Federation app.

Choose the Federated login type when you use an IAM identity provider to sign in users to your AWS account. P0 matches each requestor through the federation and grants IAM roles. This is a legacy sign-in method — AWS recommends using Identity Center.

Only Okta SAML federation is supported, via an AWS Account Federation.

An installed Okta directory integration is required. Your AWS Account Federation Okta app must be in the same Okta organization as the one installed as the directory integration.

Prerequisites

Configure federated provisioning

On the AWS IAM management configuration page, select Via a federated identity provider. Saving the configuration by clicking Next automatically applies the following changes to your AWS Account Federation app:

  • Adds a custom attribute managedByP0 to your Okta app's user profile. This lets P0 clean up dynamically assigned users from your AWS SSO Okta app.

  • Enables the Join all roles flag. This lets users assume AWS roles that P0 assigns directly to their Okta user.

P0 AWS configuration set to provision users via a federated identity provider

Last updated