Your request included an invalid saml response
Jump to navigation
Jump to search
Your request included an invalid saml response
This error can occur when the SAML response from the identity provider does not include an attribute with the Name set to
https://aws.amazon.com/SAML/Attributes/Role
The attribute must contain one or more AttributeValue
elements, each containing a comma-separated pair of strings:
* The ARN of a role that the user can be mapped to
* The ARN of the SAML provider
For more information, see Configuring SAML assertions for the authentication response. To view the SAML response in your browser, follow the steps listed in How to view a SAML response in your browser for troubleshooting.
The invalid SAML response is encountered when there are any of the below listed attribute is missing or not propagated in the right format required by AWS.
- Subject and NameID
- AudienceRestriction and Audience
- SAML
Role
Attribute - SAML
RoleSessionName
Attribute - SAML SessionDuration Attribute
Related[edit]
Activities[edit]
- Read https://dan.makovec.net/useful-stuff/sso-between-google-apps-g-suite-and-aws-console
- Set up Google Workspace SSO via SAML for Amazon Web Services
See also[edit]
- IdP, AWS IAM identity provider, Set up Google Workspace SSO via SAML for Amazon Web Services, OIDC
- SAML, IdP, AWS SAML, AWS IAM, AWS SAML endpoint,
SAML:EduPersonOrgDN, SAML Role Attribute, assume-role-with-saml
- SAML, IdP, Assertion, Attribute, SCIM, Amazon Cognito, OpenID Connect (OIDC), SAML response,
SAML:EduPersonOrgDN
, Assertion Consumer Service (ACS), SAML examples,Entity ID
,Name ID
,SAMLResponse, saml-provider, saml2aws
,aws_iam_saml_provider
- IAM: AWS IAM Identity Center, AWS Identity and Access Management, Google Cloud IAM, Azure IAM, SailPoint, CyberArk, CIAM, ForgeRock,
iam:ChangePassword
,aws iam
,AdministratorAccess
, Context keys, IAM Access Analyzer, AWS policy, AWS managed policies,IAMUserChangePassword
, AWS Roles, List of AWS policies, Resource-based policy,aws-iam-authenticator
, IRSA, RDS Authentication,AccessDenied
, AWS Authentication, AWS IAM external access analyzer
Advertising: