Hello there!

Need Help? We are right here!

miniorange Support~
miniOrange Email Support
success

Thanks for your Enquiry.

If you don't hear from us within 24 hours, please feel free to send a follow-up email to info@xecurify.com

Search Results:

×

AWS SCIM Automatic Provisioning and Deprovisioning


AWS SCIM Automatic Provisioning allows to create account in a simplified and automated way to link AWS user's account to their existing or new third party apps. AWS SCIM Provisioning automates user provisioning with their identities across the applications where users need access to. Enable automatic provisioning in Amazon Web Services (AWS) Identity center for users using Active Directory credentials.

Automated User Provisioning saves time when setting up new users and teams, and also manages access privileges through user lifecycle managemnet. miniOrange can create, read, and update user accounts for new or existing users, remove accounts for deactivated users, and synchronize attributes across multiple user stores.

AWS SCIM User provisioning and deprovisioning actions are bi-directional, so you can create accounts inside an external application and import them into miniOrange, or alternatively create the accounts in miniOrange and then push them out to any linked external applications.

AWS SCIM automatic Deprovisioning means deleting a user and removing their access from multiple applications and network systems at once. Deprovisioning action is triggered when an employee leaves a company or changes roles within the organization. The deprovisioning features increase your organization's security profile by removing access to sensitive applications and content from people who leave your organization.

Automatic Provisioning & Deprovisioning Scenarios for Amazon Web Services (AWS) Identity center


miniOrange provides Provisioning solutions for all scenarios of user management (provisioning), which includes AD Integration, LDAP Integration and automated provisioning for all External Applications such as AWS SCIM, Google Workspace, Workday, Salesforce, Microsoft apps, etc.



Follow the step-by-step guide given below to setup Automated AWS SCIM Provisioning

1. Setup Provisioning for AWS SCIM

  • Log in to the AWS Management Console.
  • Login to AWS Admin Console

  • Navigate to Security, Identity, & Compliance.
  • AWS security,identity & compliance

  • select IAM Identity Center.
  • AWS services and security

  • From the left-side, click Settings.
  • AWS settings

  • Navigate to the Identity source tab, click Actions dropdown, and select Manage provisioning.
  • AWS manage provisioning

  • On the provisioning page, copy the SCIM endpoint and Access token. These details will be required in the next step to configure user provisioning.
  • AWS SCIM endpoint & Access token

2. Configure the AWS SCIM Application in miniOrange

  • Log in to miniOrange Admin Dashboard.
  • Go to Apps and click Add Application.
  • miniOrange Admin Console showing Add Application button in Apps menu

  • In the Choose Application section, select Provisioning from All Apps dropdown.
  • miniOrange Provisioning App - Select Provisioning from dropdown

  • Search for AWS and select the AWS Sync application.
  • Search and select AWS application in miniOrange provisioning apps

  • Under Basic Settings, enter Display Application Name and click Save to add the app.
  • Adding display name for AWS provisioning application

  • In the Authorization tab enter the SCIM Base URL and Bearer Token that you copied in Step 1.
  • Click on Test Connection to verify details.
  • AWS Provisioning : Enter SCIM Base URL and Bearer Token

  • Click Test Credentials to verify the connection. Once the connection is successfully established, a Connection Successful notification will appear in the top-right corner.
  • Then, Click Save & Next to proceed to the Attributes tab.

3. Attribute Mapping

  • Under the Attributes tab, you will find two sections: Users and Groups.
  • In the Users section, map the required miniOrange Attributes to their corresponding AWS Sync Attributes.
  • Once all the required attribute mappings are configured, click Save & Next to proceed.
  • AWS SCIM Provisioning Add Attribute Mapping


4. Configure miniOrange to AWS Sync

  • In the miniOrange to AWS Sync tab, there are two sections: Users and Groups. Each section contains a list of attributes and their functions when enabled. You can enable or disable them as needed.
  • AWS SCIM Provisioning Enable appropriate option for users creation

    Attribute Description
    Users Create Users Enabling this option will create the user in the selected application upon user creation in miniOrange.
    Update Users Enabling this option will update the user profile in the selected application if updated in miniOrange.
    Delete Users Enabling this option will delete the user from the selected application if the user is deleted from the miniOrange.

    Attribute Description
    Groups Create Group Enabling this option will create the Group in the selected application upon Group creation in miniOrange.
    Delete Group Enabling this option will delete the Group from the selected application if the Group is deleted from the miniOrange.
    Add/Remove Group membership of User Enabling this option will add/remove the Group membership of a user from the selected application if the respective user group membership is updated from the miniOrange.
    Update Group Enabling this option will update the Group in the selected application upon Group updation in miniOrange.

    AWS SCIM Provisioning Enable appropriate option for groups creation

  • Click Save to apply these changes.

5. Create Group

To create a group, follow these steps:

  • From the left-hand sidebar, navigate to Groups >> Manage Groups. Click the Add Group button.
  • Click Add Group button in Manage Groups section for AWS provisioning

  • Enter a Group Name (for example, AWSProvisioning) and click Create Group.
  • Add Group Name for AWS provisioning

  • You will be redirected to the Groups List Screen when you can see the newly created group.

6. App Policy (Provision Group to AWS Sync App)

  • Navigate to Policies >> App Login Policy.
  • Click Add Policy.
  • AWS Provisioning : Navigate to Policies and click App Login Policy

  • Select the application that you configured earlier under the Apps tab (for example, AWS).
  • Select the group you created. Click Submit to create the policy. Once the policy is created successfully, a success notification will be displayed. The newly created policy will also appear under the App Login Policy section.
  • Adding App Login Policy for AWS provisioning

  • The provisioning configuration is now complete. You can proceed to verify whether user provisioning is working as expected.

7. Verify User Provisioning to AWS

  • Navigate to Groups >> Manage Groups. Click Select for the group and choose Assign Users.
  • Selecting group and assigning users for AWS provisioning

  • Ensure that the users you want to provision are already available in the miniOrange User List. If the users are not available, import or create them before proceeding.
  • From the user list, select the user(s) you want to provision to AWS. Once the users are assigned to the provisioning group, they will be automatically provisioned to AWS through the configured SCIM connection.
  • configured SCIM connection

  • Verify the users in AWS IAM Identity Center to confirm that they have been created successfully.
  • verify the users in AWS IAM Identity Center

Update and Verify a Provisioned User

To verify user update synchronization between miniOrange and AWS:

  • Navigate to Users >> User List in the miniOrange Admin Dashboard.
  • Locate the user whose details you want to modify.
  • Click the three-dot menu in the Action column, then select Edit.
  • Selecting a user from the user list to edit details

  • Update the required user attributes.
  • Click Save to apply the changes.
  • The updated user information will be automatically synchronized with AWS through SCIM provisioning.
  • Editing user details for provisioning in miniOrange portal

  • Verify the user details in AWS IAM Identity Center to confirm that the changes have been synchronized successfully.
  • Editing user details for provisioning in miniOrange portal

  • Navigate to Users >> User List in the miniOrange Admin Dashboard.
  • Locate the user you want to delete.
  • Click the three-dot menu in the Action column, then select Delete.
  • click three-dot in Action column and select Delete

  • The user will be automatically removed from AWS through SCIM provisioning.
  • Verify the user in AWS IAM Identity Center to confirm that the deletion has been synchronized successfully.
  • verify the user

Import AWS Users into miniOrange

  • To sync users from AWS to miniOrange, navigate to the AWS Sync Provisioning application in miniOrange.
  • Click on Users to Import. A pop-up window will appear.
  • click on Users to import

  • Select Import users without deleting or disabling users in miniOrange, and then click the Import button.
  • This will import and sync the users from AWS to miniOrange.
  • sync the users from AWS to miniOrange

Configure AWS SSO

  • Log in to the AWS Management Console.
  • From the AWS dashboard, click Services.
  • Under Security, Identity, & Compliance, select IAM Identity Center.
  • Navigate to the Settings section In the Identity source tab, Click the Actions dropdown and select Change identity source.
  • AWS change idp source

  • Select External identity provider, and then click Next.
  • AWS external idp

  • Under the Service provider metadata section, click Download metadata file to download the AWS service provider metadata.
  • AWS Download metadata file

  • Log in to miniOrange Admin Console.
  • Go to Apps and click on Add Application button.
  • In Choose Application Type, select SAML/WS-FED from the All Apps dropdown.
  • Search for AWS in the list, if you don't find AWS in the list then, search for custom and you can set up your application in Custom SAML App.
  • select AWS app

  • Upload the XML metadata file from AWS to the miniOrange Dashboard using the Import SP metadata feature.
  • Import SP metadata

  • In the popup, enter the Application Name, select the Upload File option and upload the XML file as shown below.
  • Upload XML File

  • After clicking the Import button, the details will be auto-populated. Click Next to proceed.
  • In the Attributes tab, make sure that the NameID format is configured as email address as shown in the image below.
  • switch to Atrribute tab

  • Click Save.
  • Now, go to the Metadata tab. Here you will see 2 sections. If you are setting up miniOrange as IdP, copy the metadata from the first section. If you need to authenticate via external IdPs (Okta, Azure AD, ADFS, OneLogin, Google Workspace), get the metadata from the External source as IdP section as shown below.
  • Click on the Download Metadata button to download the IdP metadata file which you will require further to setup SSO in AWS Console.
  • Download Metadata button to download the IdP metadata file

  • Go back to the AWS Console. Now, from the AWS console from where you downloaded the XML file, click on the Choose File button under Identity Provider Metadata, and upload the metadata file you downloaded in the previous step from the miniOrange Dashboard.
  • Accept the terms and click on Change Identity Source.
  • Aceept the terms and click change Identity Source

  • Now under the Identity Source field, you can find the link under DUAL-stack URL. Use this link for AWS SSO.


  • View Provisioning Reports

    How to access Provisioning Reports?

    • Navigate to Reports in the left-hand navigation pane, search for Provisioning, and select Provisioning Report.
    • Provisioning Report

    • Filter the reports by specifying Enduser Identifier and Application Name criteria. Additionally, choose the desired timespan for the reports. Once done, click on the Search.
    • Search Provisioning Report

    • Alternatively, you can directly click on Search to retrieve all provisioning reports based on time without applying any specific filters.


    External References

Want To Schedule A Demo?

Request a Demo
  




Our Other Identity & Access Management Products