This article provides the steps to apply Session Tags to AWS IAM Identity Center SAML configuration.
Before You Begin
Ensure SAML is configured and working. For details, refer to AWS IAM Identity Center - SAML My Page SSO Configuration - RSA Ready Implementation Guide and AWS IAM Identity Center - SAML Relying Party Configuration - RSA Ready Implementation Guide.
My Page SSO
Configure RSA Cloud Access Service
Perform these steps to configure Cloud Access Service (CAS).
Procedure
- Sign in to RSA Cloud Administration Console.
- Go to Applications > Applications.
- Locate the SAML application created for AWS IAM Identity Center and edit it.
- On the Connection Profile page, make the following updates to Statement Attributes.
Field Value/Description Statement Attributes Attribute Name https://aws.amazon.com/SAML/Attributes/AccessControl:{TagKey}
Replace {Tagkey} with your key. We have used Department here.Attribute Source Identity source available in CAS of which the user is a part, or Constant. Property Value of the Tag key. We have used eng.
- Save the changes and click Publish Changes.
Configure AWS IAM Identity Center
Perform these steps to configure AWS IAM Identity Center.
Procedure
- Log in to the AWS IAM Identity Center console.
- Under Settings > Attributes, enable Attributes for access control.
Important: Do not add any key-value pairs to the session attributes on this page. Any key-value pair added here will have precedence over the key-value pair sent by RSA.
-
In the AWS IAM Identity Center console:
-
Go to Multi-account permissions > Permission sets > Select the permission set.
-
Under the Permissions tab, locate the inline policy created and edit it.
-
Choose to add the condition and ensure you add the condition as shown in the following image.
- Verify that your policy looks like the following.
- Save the changes.
-
The configuration is complete.
Relying Party
Configure CAS
Perform these steps to configure Cloud Access Service (CAS).
Procedure
- Sign in to RSA Cloud Administration Console.
- Go to Authentication Clients > Relying Parties.
- Locate the Relying Party application created for AWS IAM Identity Center and edit it.
- On the Connection Profile page, make the following updates to Statement Attributes.
Field Value/Description Statement Attributes Attribute Name https://aws.amazon.com/SAML/Attributes/AccessControl:{TagKey}
Replace {Tagkey} with your key. We have used Department here.Attribute Source Identity source available in CAS of which the user is a part, or Constant. Property Value of the Tag key. We have used eng.
- Save the changes and click Publish Changes.
Configure AWS IAM Identity Center
Perform these steps to configure AWS IAM Identity Center.
Procedure
- Log in to the AWS IAM Identity Center console.
- Under Settings > Attributes, enable Attributes for access control.
Important: Do not add any key-value pairs to the session attributes on this page. Any key-value pair added here will have precedence over the key-value pair sent by RSA.
-
In the AWS IAM Identity Center console:
-
Go to Multi-account permissions > Permission sets > Select the permission set.
-
Under the Permissions tab, locate the inline policy created and edit it.
-
Choose to add the condition and ensure you add the condition as shown in the following image.
- Verify that your policy looks like the following.
- Save the changes.
-
The configuration is complete.
User Experience
My Page
- Log in to My Page and click the created application.
- Select the Account Name and the Role.
- Click Account.
- Verify the permissions are correctly assigned.
- Remove the attributes from CAS and notice the permissions are not available anymore.
Relying Party
Navigate to the AWS access portal URL from the IAM Identity Center console > Settings > Identity source and follow the same process as mentioned in the previous section.
Related Articles
AWS IAM Identity Center - RSA Ready Implementation Guide 44Number of Views AWS IAM Identity Center - SAML Relying Party Configuration - RSA Ready Implementation Guide 14Number of Views AWS IAM Identity Center - SAML My Page SSO Configuration - RSA Ready Implementation Guide 20Number of Views Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide 668Number of Views VMware vSphere/vCenter 8.0.2 - Authentication Agent Configuration - RSA Ready Implementation Guide 144Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA Governance & Lifecycle 8.0.0 Installation Guide Troubleshooting RSA MFA Agent for Microsoft Windows How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device