Federated
Configure the P0 AWS IAM management integration to provision users through an Okta SAML federation, granting IAM roles assigned to your AWS Account Federation app.
Choose the Federated login type when you use an IAM identity provider to sign in users to your AWS account. P0 matches each requestor through the federation and grants IAM roles. This is a legacy sign-in method — AWS recommends using Identity Center.
Prerequisites
An AWS IAM management integration installed on the target account.
An installed Okta directory integration in the same Okta organization as your AWS Account Federation app.
Configure federated provisioning
On the AWS IAM management configuration page, select Via a federated identity provider. Saving the configuration by clicking Next automatically applies the following changes to your AWS Account Federation app:
Adds a custom attribute
managedByP0to your Okta app's user profile. This lets P0 clean up dynamically assigned users from your AWS SSO Okta app.Enables the
Join all rolesflag. This lets users assume AWS roles that P0 assigns directly to their Okta user.

When you edit or make changes to your role pool, always refresh your application data. Find this action by navigating to your Okta environment as a super admin.

See Okta's Refresh application data guidance for details.
Related
Last updated