AWS Workspaces - SAML My Page SSO Configuration - RSA Ready Implementation Guide
Configure RSA Cloud Authentication Service
Perform these steps to configure RSA Cloud Authentication Service using My Page SSO.Procedure
- Enable My Page SSO by accessing the RSA Cloud Administration Console > Access > My Page > Single Sign-On (SSO). Ensure it is enabled and protected using two-factor authentication - Password and Access Policy.
- On the Applications > Application Catalog page, search for AWS and click Add to add the connection.
- On the Basic Information page, enter a name for the configuration in the Name field and click Next Step.
- On the Connection Profile page, click the IdP-initiated option.
- Provide the Service Provider details in the following format:
- ACS URL: https://signin.aws.amazon.com/saml
- Service Provider Entity ID: urn:amazon:webservices
- In the SAML Response Protection section, choose IdP signs assertion within response.
- Select the Override default signing key and certificate checkbox and click Generate Cert Bundle.
- Extract the bundle and upload the Private Key and Certificate from the bundle.
- Click Show Advanced Configuration.
- Under the User Identity section, configure Identifier Type and Property. For example, Identifier Type: Auto Detect and Property: Auto Detect.
- Under the Statement Attributes section, add the following Attributes.
- Attribute 1:
- Attribute Name - https://aws.amazon.com/SAML/Attributes/RoleSessionName
- Attribute Source - Identity Source
- Property - mail
- Attribute 2:
- Attribute Name - https://aws.amazon.com/SAML/Attributes/Role
- Attribute Source - Constant
- Property - AWS role arn value,AWS saml-provider arn value
For example:
arn:aws:iam::664847341240:role/ aws_ws_role,arn:aws:iam::664847341240:saml-provider/ aws_ws
Refer to the Configure AWS Workspaces section to obtain the AWS role arn value and AWS saml-provider arn value.
- Attribute 1:
- Provide the Default Relay State for this application and click Next Step.
- Choose your desired Access Policy for this application and click Next Step > Save and Finish.
- On the My Applications page, click the Edit drop-down icon and select Export Metadata to download the metadata.
- Click Publish Changes. Your application is now enabled for SSO.
Configure AWS Workspaces
As a prerequisite, create or register a directory for WorkSpaces by using the document - WorkSpaces management console.Perform these steps to configure AWS Workspaces.
Procedure
- Log on to AWS IAM as Root user.
- Under Access management, click Identity providers.
- Click on Add provider.
- Select SAML as Provider type.
- Scroll down and provide the following details.
- Provider name – Provide a name for your configuration.
- Metadata document – Click Choose file and upload the downloaded metadata.
- Scroll down to the bottom of the page and click Add provider.
- Click on the provider you configured.
- Copy the provider ARN value.
- Under the Access management, click Roles.
- Click Create role.
- Select the Trusted entity type as SAML 2.0 federation.
- Perform the following steps and click Next:
- SAML 2.0-based provider – Select the provider that you configured in the Identity Providers section.
- Attribute – Select the attribute as SAML:aud.
- Value – Provide the URL, https://signin.aws.amazon.com/saml which should be the same as the ACS URL that is used to configure RSA.
- Provide your desired permissions as required and click Next.
- Provide a name for the role and click Create Role.
- Click the role that you configured.
- Copy the role ARN value.
- Combine the Role ARN value followed by ‘,’ with Provider ARN value to use it as Property value in RSA.
The configuration is complete.
Return to AWS Workspaces - RSA Ready Implementation Guide.
Related Articles
AWS IAM Identity Center CloudWatch - SAML Relying Party Configuration - RSA Ready Implementation Guide 8Number of Views AWS IAM Identity Center CloudWatch - SAML My Page SSO Configuration - RSA Ready Implementation Guide 23Number of Views AWS IAM - SAML My Page SSO Configuration - RSA Ready Implementation Guide 34Number of Views Google Workspace - RSA Ready Implementation Guide 58Number of Views AWS Workspaces - RSA Ready Implementation Guide 37Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Troubleshooting AFX Server issues in RSA Identity Governance & Lifecycle RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide Downloading RSA Authentication Manager license files or RSA Software token seed records Quick Setup Guide - Connect Authentication Manager to Cloud Authentication Service
Don't see what you're looking for?