AWS IAM - SAML My Page SSO Configuration - RSA Ready Implementation Guide
Configure RSA Cloud Authentication Service
Perform these steps to configure RSA Cloud Authentication Service using My Page SSO.Procedure
- Enable My Page SSO by accessing the RSA Cloud Administration Console > Access > My Page > Single Sign-On (SSO). Ensure it is enabled and protected using two-factor authentication - Password and Access Policy.
- On the Applications > Application Catalog page, search for AWS and click Add to add the connection.
- On the Basic Information page, enter a name for the configuration in the Name field and click Next Step.
- On the Connection Profile page, click the IdP-initiated option.
- Provide the Service Provider details in the following format:
- ACS URL: https://signin.aws.amazon.com/saml
- Service Provider Entity ID: urn:amazon:webservices
- In the SAML Response Protection section, choose IdP signs assertion within response.
- Select the Override default signing key and certificate checkbox and click Generate Cert Bundle.
- Extract the bundle and upload the Private Key and Certificate from the bundle.
- Click Show Advanced Configuration.
- Under the User Identity section, configure Identifier Type and Property. For example, Identifier Type: persistent and Property: mail.
- Under the Statement Attributes section, add the following attributes.
- Attribute 1
- Attribute Name: https://aws.amazon.com/SAML/Attributes/RoleSessionName
- Attribute Source: Identity Source
- Property: mail
- Attribute 2
- Attribute Name: https://aws.amazon.com/SAML/Attributes/Role
- Attribute Source: Constant
- Property: AWS role arn value,AWS saml-provider arn value
For example:
arn:aws:iam::664847341240:role/AWSFinal,arn:aws:iam::664847341240:saml-provider/AWSFinal
Refer to the Configure AWS IAM section to obtain the AWS role arn value and AWS saml-provider arn value.
- Attribute 1
- Add the Relay State: https://console.aws.amazon.com/iam.
- Choose your desired Access Policy for this application and click Next Step > Save and Finish.
- On the My Applications page click the Edit drop-down icon and select Export Metadata to download the metadata.
- Click Publish Changes. Your application is now enabled for SSO.
Configure AWS IAM
Perform these steps to configure AWS IAM.Procedure
- Log on to AWS IAM as a root user.
- Under Access management, select Identity Providers.
- Click Add provider.
- Select SAML as Provider type.
- Scroll down and provide the following details.
- Provider name: Provide a name for your configuration.
- Metadata document: Click Choose file and upload the downloaded metadata.
- Scroll to the bottom of the page and click Add provider.
- Click the provider that you configured.
- Copy the provider ARN value.
- Under Access management, click Roles.
- Click Create role.
- Choose the Trusted entity type as SAML 2.0 federation.
- Perform the following and click Next:
- SAML 2.0-based provider: Select the provider you configured in the Identity Providers section.
- Attribute: Select the attribute as SAML:aud.
- Value: Provide this URL - https://signin.aws.amazon.com/saml. This should be the same as the ACS URL used for configuring RSA.
- Provide your desired permissions as required and click Next.
- Provide a name for the role and click Create Role.
- Click the role that you configured.
- Copy the role ARN value.
- Combine the role ARN value followed by ‘,’ with the Provider ARN value to use it as Property value in RSA.
The configuration is complete.
Return to AWS IAM - RSA Ready Implementation Guide.
Related Articles
AWS IAM Identity Center CloudWatch - SAML Relying Party Configuration - RSA Ready Implementation Guide 8Number of Views AWS IAM Identity Center CloudWatch - SAML My Page SSO Configuration - RSA Ready Implementation Guide 23Number of Views AWS Workspaces - SAML My Page SSO Configuration - RSA Ready Implementation Guide 28Number of Views AWS collector fails with NoClassDefFoundError 23Number of Views AWS IAM Identity Center S3 - SAML My Page SSO Configuration - RSA Ready Implementation Guide 24Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.9 Release Notes (January 2026) Artifacts to gather in RSA Identity Governance & Lifecycle RSA Governance & Lifecycle 8.0.0 Administrators Guide RSA Governance & Lifecycle 8.0.0 Installation Guide
Don't see what you're looking for?