Add Custom SAML Attributes to the AWS IAM Identity Center Application in Okta
Last Updated:
Overview
Administrators configuring the AWS IAM Identity Center application from the Okta Integration Network (OIN) catalog often need to add custom Security Assertion Markup Language (SAML) attributes for Attribute-Based Access Control (ABAC). The option to add custom attribute statements resides on the Sign On tab of the application settings. Administrators can add custom attributes by editing the SAML 2.0 settings within the application.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- AWS IAM Identity Center
- Security Assertion Markup Language (SAML)
- Custom Attributes
Solution
How are custom SAML attributes added to the AWS IAM Identity Center application?
Navigate to the application settings in the Okta Admin Console and edit the SAML 2.0 configuration to add custom attributes.
- Open the Okta Admin Console and navigate to Applications > Applications.
- Select the AWS IAM Identity Center application.
- Go to the Sign On tab.
- Select Edit in the Settings section.
- Scroll to the SAML 2.0 section, located below the Default Relay State field.
- Expand the Attributes section.
- Enter the custom attribute details, such as the name (
https://aws.amazon.com/SAML/Attributes/AccessControl:DataClassification)and the corresponding value (user.dataClassification). - Select Save.
