Optum / dce

Disposable Cloud Environment
Apache License 2.0
312 stars 82 forks source link

Support for AWS SSO authentication #379

Open fdeswardt opened 3 years ago

fdeswardt commented 3 years ago

Is your feature request related to a problem? Please describe. No

Describe the solution you'd like Provide ability to configure AWS SSO for authentication instead of Cognito which is the default authentication for AWS Organizations. Leverage SSO groups to assign 'users' and 'administrators' as well as consider a second group 'billing' to enable access for finance folks without giving them full admin access.

Describe alternatives you've considered Cognito with SAML 2.0 to enterprise IDP

Additional context AWS SSO has become popular for managing enterprise users' access and authorization to AWS accounts in AWS Organizations, and it will be really helpful to seamlessly integrate support for AWS SSO.

fivehorizons commented 3 years ago

I am curious also about setting up SSO and some Azure AD app listing triggers

fivehorizons commented 3 years ago

@fdeswardt tagging you check and see how this worked out?

kapilt commented 3 years ago

cognito federated identity provider can back to aws sso