Before you integrate AWS in Access Manager, you must enable web single sign-on (SSO) in the AWS console. To enable web SSO, perform the following steps:
Download the Access Manager SAML 2.0 metadata by accessing https://<www.idp.com:8443>/nidp/saml2/metadata. Save it as a local file and rename it to nam-saml2-metadata.xml.
Log in to AWS.
Click Security & Identity > Identity & Access Management > Identity Providers > Create Provider.
Specify the following details:
Provider Type: Select SAML.
Provider Name: Specify a name. For example, NAM-IDP.
Metadata Document: Select the file that you saved in Step 1.
Verify the provider information and click Create.
On the dashboard, click Roles > Create New Role.
Specify a role name.
Click Next.
Select Role for Identity Provider Access > Grant Web Single Sign-On (WebSSO) access to [SAML providers].
Click Next Step.
On the Attach Policy page, select the desired policies.
Click Next Step.
Review the role information. Make a note of the Role ARN and Trusted Entries.
Click Create Role.