Skip to content

Commit 4f28f70

Browse files
Update aws-single-sign-on-provisioning-tutorial.md
1 parent 01c6e99 commit 4f28f70

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

articles/active-directory/saas-apps/aws-single-sign-on-provisioning-tutorial.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -179,9 +179,10 @@ With PIM for Groups, you can provide just-in-time access to groups in Amazon Web
179179

180180

181181
**Enable PIM for groups**
182-
1. Create a group in Azure AD that will be used to manage access to a set of permissions in AWS.
182+
1. Create a second group in Azure AD. This group will provide access to admin permissions in AWS.
183183
1. Bring the group under [management in Azure AD PIM](https://learn.microsoft.com/azure/active-directory/privileged-identity-management/groups-discover-groups).
184184
1. Assign your test user as [eligible for the group in PIM](https://learn.microsoft.com/azure/active-directory/privileged-identity-management/groups-assign-member-owner) with the role set to member.
185+
1. Assign the second group to the AWS IAM Identity Center application.
185186

186187

187188
Now any end user that was made eligible for the group in PIM can get JIT access to the group in AWS by [activating their group membership](https://learn.microsoft.com/azure/active-directory/privileged-identity-management/groups-activate-roles#activate-a-role).

0 commit comments

Comments
 (0)