When you configure AWS roles in ºÚÁϺ£½Ç91Èë¿Ú, you need to create federated roles in AWS and collect the provider Amazon Resource Name (ARN) and the role ARNs.
To create federated role in AWS:
- Log in to the Amazon Web Services console for your organization as an administrator.
- In the main console, go to All Services.
- Under Security, Identity & Compliance, select IAM.
- In the left hand side-nav, select Roles.
- Select Create role.
- For Select type of trusted entity, select SAML 2.0 federation.
- For SAML provider, select ºÚÁϺ£½Ç91Èë¿Ú.
- Select Allow programmatic and AWS Management Console access.
- Select Next: Permissions.
- Attach the desired permission policy for the role.
- Select Next: Review
- Define a Role Name.
- Select Create role.
Collecting ARNs
To collect the provider ARN in AWS:
- Log in to the Amazon Web Services console for your organization as an administrator.
- In the main console, go to All Services.
- Under Security, Identity & Compliance, select IAM.
- Go to Providers, then select ºÚÁϺ£½Ç91Èë¿Ú.
- Collect the Provider ARN.
To collect the role ARNs in AWS:
- Log in to the Amazon Web Services console for your organization as an administrator.
- In the main console, go to All Services.
- Under Security, Identity & Compliance, select IAM.
- Go to Roles.
- Open each role to collect the Role ARN.
Back to Top