Configure Azure Active Directory single sign-on (SSO) integration with Amazon Web Services (AWS)
SCOPE
In this tutorial, you'll learn how to integrate Amazon Web Services (AWS) with Azure Active Directory (Azure AD). When you integrate Amazon Web Services (AWS) with Azure AD, you can:
- Control in Azure AD who has access to Amazon Web Services (AWS).
- Enable your users to be automatically signed-in to Amazon Web Services (AWS) with their Azure AD accounts.
- Manage your accounts in one central location - the Azure portal.
- On our DNX Foundation, we create four new accounts in the customer master account ( Shared-Services, Prod, NonProd, and Audit ). Unfortunately, Azure has a limitation of setting access to just one AWS account role. As a workaround, we will need to create one application for each account, for example, one called Shared-services, another called Prod , another called Nonprod , and the last one called Audit.
Prerequisites
To get started, you need the following items:
- An Azure AD subscription. If you don't have a subscription, you can get a .
- An AWS single sign-on (SSO) enabled subscription
Step 1 - On Azure Active Directory Create one application for each account (Shared-Services, Prod, Non-Prod and Audit)
Adding Amazon Web Services (AWS) from the gallery
To configure the integration of Amazon Web Services (AWS) into Azure AD, you need to add Amazon Web Services (AWS) from the gallery to your list of managed SaaS apps.
- Sign in to the using a Microsoft account.
- In the Azure portal, search for and select Azure Active Directory.
- Within the Azure Active Directory overview menu, choose Enterprise Applications \> All applications.
- Select New application to add an application.
- In the Add from the gallery section, type Amazon Web Services (AWS) in the search box.
- Select Amazon Web Services (AWS) from the results panel, Rename the application, for example, for Shared-Services and click on Create. Wait a few seconds while the app is added to your tenant.
- You will need to create one application for each account.
Step2 - Configure Azure AD SSO**
Follow these steps to enable Azure AD SSO in the Azure portal.
- In the , on the Amazon Web Services (AWS) application integration page, You have two options, find the Manage section and select single sign-on or you can click on Getting Started -\> 2. Set up single sign on.
- On the menu - Select a single sign-on method page, select SAML.
- You will be asked to save and test the single sign-on setting; click on " No. I'll save later" becausewe haven't configured the parameters yet.
- On the Set up single sign-on with SAML page, click the edit/pen icon for Basic SAML Configuration to edit the settings.
- Edit the identifier (Entity ID) settings, for example in the Shared-Services app set - https://signin.aws.amazon.com/saml#shared and click on save.
A suggestion for this field:
Account Name | URL |
---|---|
Master app | https://signin.aws.amazon.com/saml# |
Shared-Service app | https://signin.aws.amazon.com/saml#shared |
Non-prod app | https://signin.aws.amazon.com/saml#nonprod |
Prod app | https://signin.aws.amazon.com/saml#prod |
Audit app | https://signin.aws.amazon.com/saml#audit |
We recommend this approach for the following reasons:
- Each application provides you with
- a unique X509 certificate. Each instance of an AWS app instance can then have a different certificate expiry date, which can be managed on an individual AWS account basis. Overall certificate rollover is easier in this case.
- You do not need to set this ID for each account, but each app needs to have one unique Identifier.
- You do not need to make changes on User Attributes & Claims Edit
- On the Set up single sign-on with SAML page, in the SAML Signing Certificate (Step 3) dialog box, select Add a certificate.
7.1 - Generate a new SAML signing certificate, and then select New Certificate. Enter an email address for certificate notifications
7.2 In the SAML Signing Certificate section, find Federation Metadata XML and select Download to download the certificate and save it on your computer and send to the DNX team member.
Remember that you will need to repeat step 7.2 for all other accounts.
- You do not need to change anything on Set up < account > Shared-Services
Step3 - Configure Azure AD SSO - Audit Account**
- Follow these steps to enable Azure AD SSO in the Azure portal.
- In the , on the Amazon Web Services (AWS) Audit application integration page, You have two options, find the Manage section and select single sign-on or you can click on Getting Started -\> 2. Set up single sign on.
- On the menu - Select a single sign-on method page, select SAML.
You will be asked to save and test the single sign-on setting; click on " No. I'll save later" becausewe haven't configured the parameters yet.
On the Set up single sign-on with SAML page, click the edit/pen icon for User and attributes & Claims to edit the settings
- Select and clear the field Source attribute *.
- Type the role
- arn:aws:iam::AccountID:role/AuditAccess,arn:aws:iam::AccountID:saml-provider/Company Name and press enter
Example
arn:aws:iam::012345678900:role/AuditAccess,arn:aws:iam::012345678900:saml-provider/yourcompanyname-sso**
- Verify if the field is filled correctly and click on
Step4 - Configure Amazon Web Services (AWS) SSO
You will need to do this step on each account (Shared-Services, Prod, NonProd)
- In a different browser window, sign-on to your AWS company site as an administrator.
- Select Identity and Access Management.
- Click on Identity Providers
- Click on the Provider name - \> \<Foundation\>-SSO
- Click Upload metadata and upload the XML created on the step 7.2. and click on Upload. The SSO on each account is created in the identity stack, we just need to updated with the XML created for this specific app.
- Select Services. Under Security, Identity & Compliance, select IAM.
- In the IAM section, select Policies.
- Create a new policy by selecting Create policy for fetching the roles from the AWS account in Azure AD user provisioning.
- Create your own policy to fetch all the roles from AWS accounts.
a. In Create policy, select the JSON tab. b. In the policy document, add the following JSON:
{
"Version": "2012-10-17",
"Statement": [ { "Effect": "Allow", "Action": [ "iam:ListRoles" ], "Resource": "*" }
]
}
- Define the new policy.
a. For Name, enter \<Account\>AzureSSOListRoles, for example: SharedAzureSSOListRoles. b. For Description, enter This policy will allow to fetch the roles from AWS accounts. c. Select Create policy.
- Create a new user account in the AWS IAM service. a. In the AWS IAM console, select Users.
b. To create a new user, select Add user.
c. In the Add user section:
- Enter the user name as \<Account\>AzureSSOListRoles, for example, SharedAzureSSOListRoles.
- For the access type, select Programmatic access. This way, the user can invoke the APIs and fetch the roles from the AWS account.
- Select Next Permissions.
- Create a new policy for this user.
a. Select Attach existing policies directly.
b. Search for the newly created policy in the filter section SharedAzureSSOListRoles. c. Select the policy, and then select Next: Review.
- Review the policy to the attached user.
a. Review the user name, access type, and policy mapped to the user. b. Select Create user.
- Download the user credentials of a user.
a. Copy the user Access key ID and Secret access key. b. Enter these credentials into the Azure AD user provisioning section to fetch the roles from the AWS console. c. Select Close.
Step 5 - How to configure role provisioning in Amazon Web Services (AWS)
In the Azure AD management portal, in the AWS app, go to Provisioning.
Enter the access key and secret in the clientsecret and Secret Token fields, respectively.
a. Enter the AWS user access key in the clientsecret field.
b. Enter the AWS user secret in the Secret Token field.
c. Select Test Connection.
d. Save the setting by selecting Save.
In the Settings section, for Provisioning Status, select On. Then select Save.
Step 6 - Assign the Azure AD test user
In this section, you'll enable user to use Azure single sign-on by granting access to Amazon Web Services (AWS).
In the Azure portal, search for and select Azure Active Directory.
Within the Azure Active Directory overview menu, choose Enterprise Applications \> All applications.
In the application list, select the AWS application.
In the app's overview page, find the Manage section and select Users and groups.
Select Add user, then select Users and groups in the Add Assignment dialog.
In the Users and groups dialog, select the user from the Users list, then click the Select button at the bottom of the screen.
Select the role, in the Select Role dialog, select the appropriate role for the user from the list and then click the Select button at the bottom of the screen.
In the Add Assignment dialog, select the role desired and click the Assign button.
Ps: Instead of adding User, you can add a group as well.
Step 7 - Test the SSO Access
Install My Apps Secure Sign-in Plugin
Firefox -
Chrome -
Sign in with your Azure account
You will have access to all applications