AWS Amazon Cognito - SAML My Page SSO Configuration - RSA Ready Implementation Guide
This article describes how to integrate AWS Amazon Cognito with RSA Cloud Access Service (CAS) using My page SSO.
Configure CAS
Perform these steps to configure CAS for My Page SSO.
Procedure
- Sign in to the RSA Cloud Administration Console and browse to Applications > Application Catalog.
- Click Create from Template, and then click Select next to SAML Direct.
- On the Basic Information page, choose Cloud.
- In the Name field, enter the name for the application and click Next Step.
- On the Connection Profile page, navigate to the Initiate SAML Workflow section and choose IdP-initiated.
- Under Data Input Method, choose Import Metadata.
- Click Choose File and import the metadata file downloaded from AWS Amazon Cognito to populate the ACS URL and Service Provider Entity ID.
- In the Message Protection section, choose IdP signs entire SAML response.
- Click Download Certificate.
- Under the User Identity section, select the following values:
- Identifier Type: unspecified
- Property: mail
- On the User Access page, choose the access policy you want to use to determine which users can access the application, and then click Next Step.
- On the Portal Display page, configure the portal display and other settings.
- Click Next Step.
- On the Fulfillment page, configure your preferred settings or leave the Fulfillment toggle disabled, and then click Save and Finish.
- Click Publish Changes and wait for the operation to be completed.
After publishing, your application is now enabled for SSO. - Navigate to the newly created application from Applications.
- In the Edit drop-down list, choose Export Metadata. This metadata will be used later in the AWS Amazon Cognito configuration.
Configure AWS Amazon Cognito
Perform these steps to configure AWS Amazon Cognito Security Intelligence Platform (SIP).
Procedure
- Log in to the AWS Amazon Cognito tenant with an administrator account.
- In the left pane, navigate to Identity Pools and click Create Identity pool.
- Under Configured Identity Pool trust, perform the following steps.
- Select the Authenticated access checkbox.
- Select the SAML checkbox and click Next.
- Under Configure permissions, perform the following steps:
- In the IAM role section, choose Create a new IAM role.
- In the IAM role name section, provide the IAM role name as shown in the following image.
- In the Connect Identity Providers SAML section, click Create new provider.
- In the Provider type section, choose SAML.
- Click Choose file to import the metadata downloaded from CAS.
- Click Add provider to create the SAML identity provider.
- In the Connect identity providers section, provide the following details:
- In the SAML identity provider section, select the RSASSOCoginito identity.
- In the Role Settings section, choose Use default authenticated role.
- In the Claim mapping section, choose Inactive.
- Under Configure properties, provide the Identity pool name as shown in the following image.
- Select the Active basic flow (Basic authentication) checkbox and click Next to review and create the identity pool.
- Review the identity pool and click Create identity pool to complete the identity pool creation.
- In the Amazon Cognito console, under App clients, choose your user pool.
- In the navigation pane, under Applications, choose App clients > My web app.
- On the App clients and analytics page, navigate to the Login pages section.
- Under the Managed login pages configuration section, choose Edit.
- In the Identity providers drop-down list, select Cognito user pool.
- In the OAuth 2.0 grant types section, select Implicit grant.
- In the OpenID Connect scopes section, select Email and OpenID.
- Click Save changes to complete the settings.
The configuration is complete.
Related Articles
AWS Amazon Cognito - SAML Relying Party Configuration - RSA Ready Implementation Guide 1Number of Views Palo Alto NGFW Global Protect - SAML My Page SSO Configuration - RSA Ready Implementation Guide 44Number of Views Salesforce - SAML My Page SSO Configuration - RSA Ready Implementation Guide 66Number of Views Delinea - SAML My Page SSO Configuration - RSA Ready Implementation Guide 14Number of Views SilverFort - SAML My Page SSO Configuration - RSA Ready Implementation Guide 3Number of Views
Trending Articles
Troubleshooting RSA SecurID Access Identity Router to RSA Authentication Manager test connection failures RSA SecurID Software Token 5.0.2 Downloads for Microsoft Windows RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Governance & Lifecycle 8.0.0 Administrators Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory
Don't see what you're looking for?