These steps will guide you through setting up single sign-on (SSO) for for Amazon Web Services (AWS) for a single role. If you want to set up SSO that supports multiple AWS roles or accounts, see Configuring SAML for Amazon Web Services (AWS) with Multiple Accounts and Roles.
Tip: In some cases, a field macro or custom user field can be used. This feature requires a OneLogin subscription with the Advanced Directory add-on.
Sign in to the OneLogin administrator dashboard and go to Apps > Add Apps.
Search for and select Amazon Web Services (AWS).
Edit the application's name and display information if desired, and click Save.
In the SSO tab, copy and paste the Issuer URL into your browser's address bar to download the metadata XML document for use in a later step.

Open a new browser tab and sign in to your AWS Management Console. Go to IAM, then Identity Providers.

Select Create SAML Provider. In the prompt that appears, provide a name for the Identity Provider, such as OneLogin.
Upload the metadata XML document you previously downloaded from the SSO tab in OneLogin.
For the Provider, select OneLogin.


Go to Roles and click Create New Role.
Give your role a user-friendly name, then for Role Type, choose Role For Identity Provider Access.
Click Grant Web Single Sign-On (Web SSO) access to SAML Providers and choose the SAML provider you created above.
Choose the permissions that federated users will inherit when using this role and review your settings to complete the role creation.


role-arn,provider-arn
arn:aws:iam::222222222222:role/sso,arn:aws:iam::222222222222:saml-provider/OneLogin+ = , . @ - _Click Save again. Your SAML connection is complete!