AWS Security ChangesHomeSearch

AWS singlesignon: Clarified external IdP requirements for portal access

Service: singlesignon · 2026-07-29 · Documentation low

File: singlesignon/latest/userguide/multi-region-workforce-access.md

Summary

Added notes restricting certain configurations to external IdP users

Security assessment

Prevents misconfiguration by clarifying identity source requirements for specific features

Evidence

+###### Note
+
+This section applies only to instances that use an external identity provider (IdP).

Diff

diff --git a/singlesignon/latest/userguide/multi-region-workforce-access.md b/singlesignon/latest/userguide/multi-region-workforce-access.md
index b36f2a502..f15819031 100644
--- a//singlesignon/latest/userguide/multi-region-workforce-access.md
+++ b//singlesignon/latest/userguide/multi-region-workforce-access.md
@@ -13 +13 @@ This section explains how your workforce can access the AWS access portal, AWS a
-The AWS access portal in an additional Region displays the AWS accounts and applications your workforce has access to in the same way as in the primary Region. Your workforce can sign into the AWS access portal in an additional Region through a direct link to the regional portal endpoint (for example, `https://ssoins-111111h2222j33pp.eu-west-1.portal.amazonaws.com`) or through a [bookmark app](./replicate-to-additional-region.html#update-external-idp-setup) you set up in the external IdP. 
+The AWS access portal in an additional Region displays the AWS accounts and applications your workforce has access to in the same way as in the primary Region. Your workforce can sign into the AWS access portal in an additional Region through a direct link to the regional portal endpoint (for example, `https://ssoins-111111h2222j33pp.eu-west-1.portal.amazonaws.com`). If you use an external identity provider, your workforce can also sign in through a [bookmark app](./replicate-to-additional-region.html#update-external-idp-setup) you set up in the external IdP. 
@@ -54,0 +55,4 @@ Dual-stack2 | Yes | Yes |  **Pattern:** `https://`[Identity Center instance ID]`
+###### Note
+
+This section applies only to instances that use an external identity provider (IdP). If you use the Identity Center directory as your identity source, ACS URL configuration is not required.
+
@@ -81,0 +86,4 @@ Dual-stack | Yes | Yes |  **Pattern:** `https://`[Region]`.sso.signin.aws/platfo
+###### Note
+
+This section applies only to instances that use an external identity provider (IdP). If you use the Identity Center directory as your identity source, this limitation does not apply.
+