AWS singlesignon: Clarified external IdP-specific troubleshooting
Summary
Added specificity to external IdP requirements in error resolution guidance
Security assessment
Improves accuracy of troubleshooting steps to prevent misconfigurations in external IdP integrations
Evidence
-If no IAM Identity Center users can sign into AWS managed applications in an additional Region after you added the Region in IAM Identity Center, confirm that you configured the additional Region's Assertion Consumer Service (ACS) URL in the external identity provider as described in [Step 3: Update external IdP setup](./replicate-to-additional-region.html#update-external-idp-setup).
Diff
diff --git a/singlesignon/latest/userguide/multi-region-related-errors.md b/singlesignon/latest/userguide/multi-region-related-errors.md index 612270cc2..bc1f1cc66 100644 --- a//singlesignon/latest/userguide/multi-region-related-errors.md +++ b//singlesignon/latest/userguide/multi-region-related-errors.md @@ -19 +19 @@ You must first create a replica key for your customer managed KMS key in the Reg -If no IAM Identity Center users can sign into AWS managed applications in an additional Region after you added the Region in IAM Identity Center, confirm that you configured the additional Region's Assertion Consumer Service (ACS) URL in the external identity provider as described in [Step 3: Update external IdP setup](./replicate-to-additional-region.html#update-external-idp-setup). Also, confirm your users have connectivity to the Region. +If no IAM Identity Center users can sign into AWS managed applications in an additional Region after you added the Region in IAM Identity Center, confirm that you configured the additional Region's Assertion Consumer Service (ACS) URL in the external identity provider as described in [Step 3 (external identity providers only): Update external IdP setup](./replicate-to-additional-region.html#update-external-idp-setup). Also, confirm your users have connectivity to the Region.