3 ms·
Hi there. I'm confused by your statement that "The integration guide recommends connecting the identity provider to each AWS account ..." This used to be the w
by exidy 9y ago
Hi there. I'm confused by your statement that "The integration guide recommends connecting the identity provider to each AWS account ..."
This used to be the way Okta recommended integrating to AWS, but in the guide you linked[1] they are using pretty much exactly the same approach you did - authentication to an identity account (ops account in your terminology) then assume-role into the target account.
I can't see any major differences between the standard Okta approach and the way you outlined in your blog. Could let me know if I missed something?
[1] https://support.okta.com/help/servlet/fileField?retURL=/help/articles/Knowledge_Article/Amazon-Web-Services-and-Okta-Integration-Guide&entityId=ka0F0000000MeyyIAC&field=File_Attachment__Body__s https://support.okta.com/help/servlet/fileField?retURL=/help...