Amazon AWS Apps Portal

Enable Single Sign-On (SSO) for AWS Apps Portal with UserLock to centralize authentication, enforce access policies, and secure access to SaaS applications managed through AWS.

Published September 9, 2025

Introduction

This guide explains how to integrate AWS Apps Portal with UserLock Single Sign-On (SSO) using AWS SSO as a service provider.

By configuring UserLock SSO as the Identity Provider (IdP) for AWS SSO, you can protect all SaaS applications federated within the AWS Apps Portal using UserLock access policies (MFA, time, machine, or location restrictions) on SSO sessions.

🚩️ Before starting:

Note

In this example, we show how to configure Dropbox with AWS SSO.
Each SaaS application has its own requirements, so refer to the official documentation for detailed steps specific to the app you want to integrate.

Step 1. Configure AWS SSO for the application

  1. In AWS SSO, go to Applications ▸ Add a new application.

  2. Search for Dropbox, select it, and click Add application.

  3. Download the AWS SSO certificate.

  4. In the Assigned users tab, add the test account that will be used for validation.

Step 2. Configure the SaaS application (Dropbox example)

  1. In another browser tab, open the Dropbox admin console.

  2. Go to Settings ▸ Single Sign-On.

  3. Complete the form as follows:

    Settings

    Values

    Identity Provider Login URL

    Enter the AWS SSO sign-in URL

    Identity Provider Logout URL (optional)

    Enter the AWS SSO sign-out URL

    X.509 certificate

    Upload the AWS SSO certificate downloaded earlier

  4. Save and test the setup.

Step 3. Test the configuration

  1. Open the User Portal URL (available in AWS SSO Settings).

  2. Select Dropbox from the list of applications.

  3. Confirm that authentication is performed through UserLock SSO.

Next steps

You can extend the security of SSO sessions by applying UserLock access policies in addition to authentication.