AWS Amazon Cognito - SAML Relying Party Configuration - RSA Ready Implementation Guide
This article describes how to integrate AWS Amazon Cognito with RSA Cloud Access Service (CAS) using Relying Party.
Configure CAS
Perform these steps to configure CAS using Relying Party.
Procedure
- Sign in to the RSA Cloud Administration Console.
- Click Authentication Clients > Relying Parties.
- On the My Relying Parties page, click Add a Relying Party.
- On the Relying Party Catalog page, click Add for Service Provider SAML.
- On the Basic Information page, enter the name for the application in the Name field.
- Click Next Step.
- On the Authentication page, select RSA manages all authentication.
- In the 2.0 Access Policy for Authentication drop-down list, select a policy that was previously configured, and then select Next Step.
- Under Data Input Method, choose Import Metadata.
- Click Choose File and import the metadata downloaded from AWS Amazon Cognito to populate the ACS URL and Service Provider Entity ID.
- Under the Message Protection section, choose IdP signs entire SAML response.
- Scroll down to the User Identity section and select the following values:
- Identifier Type: unspecified
- Property: mail
- Click Save and Finish.
- Click Publish Changes and wait for the operation to be completed.
- Under My Relying Parties, navigate to the newly created relying party.
- In the Edit drop-down list, choose Metadata.
Configure AWS Amazon Cognito
Perform these steps to configure AWS Amazon Cognito Security Intelligence Platform (SIP).
Procedure
- Log in to the AWS Amazon Cognito tenant with an administrator account.
- In the left pane, navigate to Identity Pools and click Create Identity pool.
- Under Configured Identity Pool trust, perform the following steps.
- Select the Authenticated access checkbox.
- Select the SAML checkbox and click Next.
- Under Configure permissions, perform the following steps:
- In the IAM role section, choose Create a new IAM role.
- In the IAM role name section, provide the IAM role name as shown in the following image.
- In the Connect Identity Providers SAML section, click Create new provider.
- In the Provider type section, choose SAML.
- Click Choose file to import the metadata downloaded from CAS.
- Click Add provider to create the SAML identity provider.
- In the Connect identity providers section, provide the following details:
- In the SAML identity provider section, select the RSASSOCoginito identity.
- In the Role Settings section, choose Use default authenticated role.
- In the Claim mapping section, choose Inactive.
- Under Configure properties, provide the Identity pool name as shown in the following image.
- Select the Active basic flow (Basic authentication) checkbox and click Next to review and create the identity pool.
- Review the identity pool and click Create identity pool to complete the identity pool creation.
- In the Amazon Cognito console, under App clients, choose your user pool.
- In the navigation pane, under Applications, choose App clients > My web app.
- On the App clients and analytics page, navigate to the Login pages section.
- Under the Managed login pages configuration section, choose Edit.
- In the Identity providers drop-down list, select Cognito user pool.
- In the OAuth 2.0 grant types section, select Implicit grant.
- In the OpenID Connect scopes section, select Email and OpenID.
- Click Save changes to complete the settings.
The configuration is complete.
Related Articles
AWS Amazon Cognito - SAML My Page SSO Configuration - RSA Ready Implementation Guide 1Number of Views AWS Amazon Cognito - RSA Ready Implementation Guide 2Number of Views Palo Alto NGFW Global Protect - SAML Relying Party Configuration - RSA Ready Implementation Guide 110Number of Views Workday - SAML Relying Party Configuration - RSA Ready Implementation Guide 4Number of Views Microsoft Entra ID External Authentication Methods (EAM) - Relying Party Configuration Using OIDC - RSA Ready Implementati… 509Number of Views
Trending Articles
Troubleshooting RSA SecurID Access Identity Router to RSA Authentication Manager test connection failures RSA SecurID Software Token 5.0.2 Downloads for Microsoft Windows RSA Authentication Manager 8.9 Release Notes (January 2026) Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.8 Setup and Configuration Guide
Don't see what you're looking for?