Overview
- AWS Single Sign-On is a cloud-based single sign-on (SSO) service that makes it easy to centrally manage SSO access to all of your AWS accounts and cloud applications.
- Specifically, it helps you manage SSO access and user permissions across all your AWS accounts in AWS Organizations.
- AWS SSO includes a user portal where your end-users can find and access all their assigned AWS accounts, cloud applications, and custom applications in one place.
AWS Single Sign-On concepts
- AWS SSO manages access to all your AWS Organizations accounts, AWS SSO-integrated applications, and other business applications that support the Security Assertion Markup Language (SAML) 2.0 standard.
- Users
- When working in AWS SSO, users must be uniquely identifiable.
- Groups
- Groups are a logical combination of users that you define.
- You can create groups and add users to the groups.
- AWS SSO does not support adding a group to a group (nested groups).
- You can create users and groups directly in AWS SSO, or work with users and groups you have in Active Directory or an external identity provider.
- User and gr