UserLock Documentation
UserLock Documentation

Configure AWS for UserLock SSO

As a prerequisite, you need to create an AWS Organization account.

  1. Open the AWS console
  2. Enable AWS SSO
  3. In the Settings, change the Identity Source to External Identity Provider.
  4. Under Identity Provider metadata, upload the UserLock SSO metadata XML file (https://<your_ul_sso_url>/metadata).
  5. In AWS accounts node, check the AWS account and click Assign Users. Add the user account you want to test with.
  6. Launch the User portal URL (located in AWS SSO Settings).

Configure AWS in UserLock console

In the UserLock console, Navigate to Single Sign-On → Configuration.

  1. Select Add configuration, then select AWS as the provider to be configured.
  2. AWS SSO issuer URL and AWS SSO ACS URL are available in AWS SSO console.

    AWS SSO console
  3. For the Email domain, enter the domain of the email users will use to connect.

Change the SAML certificate

To update the SAML certificate in AWS SSO, you need to upload the new SAML metadata to AWS.

To do this, go in AWS SSO Settings. In Identity Source click on the Change button. Finally, put the UserLock SSO metadata url in Idp SAML metadata (https://<your_ul_sso_url>/metadata)

Amazon AWS Portal

For more information about the Amazon AWS Portal, please consult this page.