Technical Tip: FortiSASE SSO Integration with AWS IAM Identity Center as IdP
| Description | This article describes how to integrate FortiSASE with AWS IAM Identity Center using SAML for Single Sign-On (SSO). It also explains how to map AWS user groups to FortiSASE remote user groups based on SAML assertion attributes, enabling identity-based access control. |
| Scope | FortiSASE. |
| Solution | Overview:
Prerequisites:
Step-by-step configuration guide:
Configure attribute mappings in AWS IAM Identity Center to include group information and username in the SAML assertion. The Object ID of the AWS group is sent as a SAML attribute. This value will later be used by FortiSASE to map users to remote user groups. The assertion attributes names must match FortiSASE configuration; in this case, the username and group that are FortiSASE default values are used. If different attribute names are used, FortiSASE configuration must also be changed.
Once the application is created and configured in AWS, get the URLs and the IDP certificate from the AWS console.
Configure FortiSASE SSO.
When a user authenticates, FortiSASE evaluates the SAML assertion. If the group Object ID matches, the user is automatically mapped to the corresponding FortiSASE user group.
|
















