AWS Security ChangesHomeSearch

AWS singlesignon: Clarified external IdP-specific troubleshooting

Service: singlesignon · 2026-07-29 · Documentation low

File: singlesignon/latest/userguide/multi-region-related-errors.md

Summary

Added specificity to external IdP requirements in error resolution guidance

Security assessment

Improves accuracy of troubleshooting steps to prevent misconfigurations in external IdP integrations

Evidence

-If no IAM Identity Center users can sign into AWS managed applications in an additional Region after you added the Region in IAM Identity Center, confirm that you configured the additional Region's Assertion Consumer Service (ACS) URL in the external identity provider as described in [Step 3: Update external IdP setup](./replicate-to-additional-region.html#update-external-idp-setup).

Diff

diff --git a/singlesignon/latest/userguide/multi-region-related-errors.md b/singlesignon/latest/userguide/multi-region-related-errors.md
index 612270cc2..bc1f1cc66 100644
--- a//singlesignon/latest/userguide/multi-region-related-errors.md
+++ b//singlesignon/latest/userguide/multi-region-related-errors.md
@@ -19 +19 @@ You must first create a replica key for your customer managed KMS key in the Reg
-If no IAM Identity Center users can sign into AWS managed applications in an additional Region after you added the Region in IAM Identity Center, confirm that you configured the additional Region's Assertion Consumer Service (ACS) URL in the external identity provider as described in [Step 3: Update external IdP setup](./replicate-to-additional-region.html#update-external-idp-setup). Also, confirm your users have connectivity to the Region. 
+If no IAM Identity Center users can sign into AWS managed applications in an additional Region after you added the Region in IAM Identity Center, confirm that you configured the additional Region's Assertion Consumer Service (ACS) URL in the external identity provider as described in [Step 3 (external identity providers only): Update external IdP setup](./replicate-to-additional-region.html#update-external-idp-setup). Also, confirm your users have connectivity to the Region.