To give Microsoft Entra ID users single sign-on to AWS accounts, add the AWS IAM Identity Center gallery app in Entra ID, exchange SAML metadata between the app and IAM Identity Center's Change identity source wizard (choosing External identity provider), then enable automatic provisioning in IAM Identity Center and paste its SCIM endpoint and access token into the app's provisioning settings. Entra ID then creates users and groups in IAM Identity Center every provisioning cycle, and you grant AWS access by assigning those groups to permission sets on each AWS account.
Who this is for and what you will have
This guide is for identity and cloud administrators who already run Microsoft Entra ID and want AWS access to follow the same joiner, mover and leaver process, MFA and Conditional Access as Microsoft 365. It assumes AWS Organizations with IAM Identity Center enabled.
At the end you will have:
- Microsoft Entra ID as the external identity provider for IAM Identity Center over SAML 2.0.
- Users and groups provisioned automatically from Entra ID with SCIM 2.0.
- Permission sets assigned to Entra groups on your AWS accounts.
- A tested sign-in path through My Apps and the AWS access portal.
- A token rotation routine and fixes for the common sync errors.
Once people can sign in, the companion guide Amazon S3 for Azure admins shows how to secure the data they'll reach. For the access model around it, see the zero trust remote access architecture.
How the pieces fit together
Microsoft Entra ID AWS IAM Identity Center
------------------- ------------------------
Enterprise app "AWS IAM Identity Center"
SAML SSO ---- assertion (NameID) ----> External identity provider
Provisioning (SCIM 2.0) -- users/groups -> SCIM endpoint + bearer token
Assigned groups Users and groups (Created by SCIM)
|
Permission sets
|
AWS account assignments
|
IAM roles in each accountSAML authenticates the user, but it can't create users in AWS. SCIM creates and updates the users and groups. Permission sets decide what those users can do in each account. You need all three.
Prerequisites
- AWS: an AWS Organizations organization with an organization instance of IAM Identity Center. Microsoft's tutorial recommends delegating a member account as the IAM Identity Center administrator and configuring SSO there rather than in the management account.
- Entra roles: Cloud Application Administrator, Application Administrator or owner of the enterprise application.
- Licensing: assigning groups (rather than individual users) to an enterprise application requires Microsoft Entra ID P1 or P2.
- User attributes: every user to be provisioned needs a first name, last name, display name and user name. Users missing any of these aren't provisioned.
- A maintenance window if you already have users in the Identity Center directory, because the identity source change affects how they sign in.
Plan identifiers before you click anything
Most failed rollouts come down to identifier mismatches. Decide these up front:
| Item | Recommendation |
|---|---|
| SAML NameID | Use the attribute you map to SCIM userName, usually the UPN. If they differ, sign-in fails. |
SCIM userName | Unique, non-null sign-in identifier, typically userPrincipalName. |
| SCIM primary email | Must be unique per user; map a real, non-null address. |
SCIM externalId | A value that never changes, such as the Entra object ID, so renames don't break assignments. |
| Multi-valued attributes | Send one value only; AWS rejects multiple emails or phone numbers. |
| Group design | Assign flat groups directly; nested groups aren't provisioned. |
If existing IAM Identity Center users were created manually, their user names must match what Entra ID sends as the NameID, or their assignments won't apply after the switch.
Step 1: Add the AWS IAM Identity Center app in Entra ID
- Sign in to the Microsoft Entra admin center as at least a Cloud Application Administrator.
- Browse to Entra ID > Enterprise apps > New application.
- Search the gallery for AWS IAM Identity Center, select it and create it.
- Under Users and groups, assign one test user for now. You'll add groups after provisioning works.
Step 2: Start the identity source change in IAM Identity Center
- Open the IAM Identity Center console and choose Settings.
- On the Identity source tab, choose Actions > Change identity source.
- Select External identity provider and choose Next.
- Under Service provider metadata, choose the endpoint type (Default IPv4 or Dual-stack), copy the AWS access portal sign-in URL, and download the service provider metadata file if the page offers it. AWS's current tutorial notes that the metadata file may only become downloadable after the identity source change is complete; in that case note the IAM Identity Center issuer URL and ACS URL shown on the page so you can enter them manually in Entra ID.
- Leave this page open.
Step 3: Configure SAML in Entra ID
- In the Entra admin center open the AWS IAM Identity Center app and select Single sign-on > SAML.
- Edit Basic SAML Configuration, select Upload metadata file and upload the AWS service provider metadata. The Identifier (the IAM Identity Center issuer URL) and Reply URL (Assertion Consumer Service URL) fill in automatically; if they don't, enter them manually.
- In Sign on URL, paste the AWS access portal sign-in URL and select Save. Choose not to test yet.
- In SAML Certificates, download the Federation Metadata XML.
If you later replicate IAM Identity Center to additional AWS Regions, add each Region's ACS URL as an extra Reply URL and keep the primary Region's as the default.
Step 4: Finish the identity source change in AWS
- Return to the open Configure external identity provider page.
- Under Identity provider metadata, choose Choose file for IdP SAML metadata and upload the Entra federation metadata.
- Choose Next, read the warning, type ACCEPT and choose Change identity source.
According to AWS, when you change from the Identity Center directory to an external IdP, existing user and group assignments and group memberships continue to work as long as Entra sends assertions that match the existing user names. Active AWS access portal sessions continue until the configured session duration expires; revoke them from the console if needed. You can revert to the Identity Center directory later, and AWS preserves assignments when you do.
Step 5: Enable automatic provisioning in IAM Identity Center
- In Settings > Identity source, find the Automatic provisioning box and choose Enable.
- In the Inbound automatic provisioning dialog, copy the SCIM endpoint, which looks like
https://scim.<aws-region>.amazonaws.com/<id>/scim/v2(or theapi.awsdual-stack form). - Choose Show token and copy the Access token. This is the only time you can see it.
- Choose Close. Provisioning method now shows SCIM.
After this point you can no longer add or edit users in the IAM Identity Center console; all changes come from Entra ID.
Step 6: Configure provisioning in Entra ID
- In the Entra app, open Provisioning and create a new configuration with Automatic mode.
- Paste the SCIM endpoint into Tenant URL and the access token into Secret Token.
- Select Test Connection; you should see that the credentials are authorized. Save or create the configuration.
- In Properties, add a notification email for quarantine alerts and enable accidental deletion prevention.
- Open Attribute Mapping > users and review the mappings.
userNameis the matching attribute. Remove duplicate mappings that feedphoneNumbersoremails, because AWS accepts only one value for each. - Open Attribute Mapping > groups.
displayNameis the matching attribute andmemberscarries memberships. - Under Users and groups, assign the security groups that should reach AWS, for example
AWS-Admins,AWS-DevelopersandAWS-ReadOnly. - Use Provision on demand for one user and one group to validate, then select Start provisioning on the Overview page.
The first cycle provisions everyone in scope. After that, incremental cycles run every 40 minutes.
Step 7: Assign permission sets to the provisioned groups
- In the IAM Identity Center console, under Multi-account permissions, choose Permission sets > Create permission set. Use a predefined permission set based on an AWS managed policy such as AdministratorAccess, or a custom permission set with an inline policy. The default session duration is one hour.
- Choose AWS accounts, select the accounts, and choose Assign users or groups.
- On the Groups tab select the provisioned Entra groups, select the permission sets, and choose Submit.
Users then pick the account and permission set in the AWS access portal and are signed in with that permission set's permissions. Grant access to groups rather than individual users so that Entra group membership remains the single place where access changes.
Optional: ABAC and just-in-time access
Attributes for access control. Enable the feature in IAM Identity Center, then in the Entra app's Attributes & Claims add claims named AccessControl:<AttributeName> with namespace https://aws.amazon.com/SAML/Attributes, for example AccessControl:Department sourced from user.department. These arrive as session tags that your IAM policies can test. If an attribute is later removed from a user in Entra ID, AWS documents that it isn't removed from the user in IAM Identity Center.
PIM for Groups. Put a privileged group such as AWS-Admins-JIT under Privileged Identity Management, make users eligible rather than permanent members, assign the group to the app and give it an admin permission set. When a user activates membership, it's provisioned to AWS within 2 to 10 minutes; Microsoft documents throttling at five requests per 10 seconds per application, after which changes wait for the next 40-minute cycle. Deactivation happens in the regular incremental cycle, not immediately.
Verify the setup
- In the IAM Identity Center console, choose Users. Provisioned users show SCIM in the Created by column; open one and confirm first name, last name and other mapped attributes.
- From a workstation with the AWS CLI, list the users in the identity store:
aws sso-admin list-instances --query "Instances[].[InstanceArn,IdentityStoreId]" --output text
aws identitystore list-users --identity-store-id d-1234567890- Sign in to My Apps as a test user and select the AWS IAM Identity Center tile. You should land in the AWS access portal with the assigned accounts and permission sets listed. Selecting a permission set's Management console link opens the console in that role.
- In Entra ID, check the Provisioning logs for skipped or failed users.
Rotate the SCIM token every year
SCIM access tokens are valid for one year, and provisioning stops when the token expires. AWS starts reminding you 90 days before expiry. A directory holds at most two tokens, so:
- In IAM Identity Center, choose Settings > Identity source > Actions > Manage provisioning and note the current token ID.
- Generate a new token (delete an expired or unused one first if you already have two).
- Paste the new token into Secret Token in the Entra app, select Test Connection and save.
- Confirm a provisioning cycle succeeds, then delete the old token.
Put a calendar reminder or ticket on the expiry date regardless of the AWS reminders.
Troubleshooting
Provisioning logs show "Request is unparsable, syntactically incorrect, or violates schema" with status 400. In CloudTrail the CreateUser event shows Currently list attributes only allow single item. A user has more than one value for a multi-valued attribute such as phone numbers. Reduce it to one value or remove the duplicate mapping.
Users are skipped for missing attributes. First name, last name, display name and user name are all required. Populate givenName and surname in Entra ID.
Users in a nested group never appear in AWS. Only direct members of assigned groups are provisioned. Assign the inner group directly.
Guest users fail to sync or sign in. Guest UPNs contain #EXT#, which IAM Identity Center doesn't expect. In Attributes & Claims, add claim conditions on Unique User Identifier (Name ID): members use user.userprincipalname, external guests use user.mail.
Sign-in reaches AWS but fails. The SAML NameID doesn't match the provisioned userName. Make both use the same source attribute.
Changes take up to 40 minutes to appear. That's the incremental cycle. Use provision on demand for urgent changes, and remember that deleting or disabling a user doesn't immediately end sessions that are already active.
Users or attributes contain characters AWS rejects. IAM Identity Center doesn't accept some characters Entra allows, including tabs, new lines and characters such as <, >, ;, : and %. Clean up the source value.
Test Connection fails. Check that the Tenant URL and Secret Token were copied in full from the IAM Identity Center dialog and that the token hasn't expired or been deleted. If in doubt, generate a new token and retry.
Closing checklist
- IAM Identity Center configured in a delegated administrator account, identity source set to External identity provider.
- SAML metadata exchanged both ways, sign-on URL set, test user signs in from My Apps.
- NameID and SCIM
userNameuse the same attribute;externalIdmaps to an immutable value. - Automatic provisioning enabled, token stored securely, expiry date tracked, rotation steps documented.
- Only flat security groups assigned; multi-valued attribute mappings cleaned up.
- Permission sets assigned to groups, not users; privileged access through PIM for Groups.
- Provisioning notification email and accidental deletion prevention configured.
References
- Configure SAML and SCIM with Microsoft Entra ID and IAM Identity Center
- Provision users and groups from an external identity provider using SCIM
- Rotate an access token
- Considerations for changing your identity source
- Configure AWS IAM Identity Center for single sign-on with Microsoft Entra ID
- Configure AWS IAM Identity Center for automatic user provisioning with Microsoft Entra ID
- Manage users and groups assignment to an application
- AWS CLI identitystore list-users
- AWS CLI sso-admin list-instances