简体   繁体   English

AWS SSO 不由 Control Tower 管理

[英]AWS SSO not managed by Control Tower

What I'm trying to achieve我想要达到的目标

When trying to manage users in Control Tower I'm seeing this:在尝试管理控制塔中的用户时,我看到了这个:

这个

(This page applies only to customers using an SSO directory managed by AWS Control Tower - for Google basically, I couldn't find it there) (此页面仅适用于使用由 AWS Control Tower 管理的 SSO 目录的客户 - 基本上对于 Google,我在那里找不到它)

I don't have specific goal regarding this error I'm simply afraid it might prevent me from doing something in the future.我没有关于这个错误的具体目标我只是担心它可能会阻止我将来做某事。

What I did我做了什么

I first created the AD Connector connection to my self-hosted AD, then connected this directory to SSO, afterwards I created Control Tower (Due to an error message saying I cannot provision Control Tower without SSO).我首先创建了与我的自托管 AD 的 AD 连接器连接,然后将此目录连接到 SSO,然后我创建了 Control Tower(由于错误消息说我无法在没有 SSO 的情况下配置 Control Tower)。

Some more weird behavior一些更奇怪的行为

Under User portal URL there's a never ending spinner and I'm not sure if there's any setting I can change from the SSO side to affect this error (correct me if I'm wrong).在用户门户 URL 下,有一个永无止境的微调器,我不确定是否可以从 SSO 端更改任何设置以影响此错误(如果我错了,请纠正我)。

Sounds like you're wondering if this error means you'll be missing out on something.听起来你想知道这个错误是否意味着你会错过一些东西。 The answer: you do not need to worry about it since you're using your own solution for this aspect of AWS Control Tower: identity, access management and SSO.答案:您无需担心,因为您使用自己的解决方案来处理 AWS Control Tower 的这方面:身份、访问管理和 SSO。

I think the best way to show you what you're missing out on (but don't need) is with a few screenshots, as of the October 2020 edition of the AWS Management Console.我认为,从 2020 年 10 月版的 AWS 管理控制台开始,向您展示您遗漏(但不需要)什么的最佳方式是使用一些屏幕截图。

What this page (AWS Control Tower > Users and access) would show you if you had let AWS Control Tower set up the default AWS SSO for you:如果您让 AWS Control Tower 为您设置默认 AWS SSO,此页面(AWS Control Tower > 用户和访问)将向您显示什么: 默认的 AWS Control Tower“用户和访问”页面

And if you follow the link to "View in AWS Single Sign-On", you'll be able to see AWS SSO's mappings between Users, Permission sets and Accounts:如果您点击“在 AWS Single Sign-On 中查看”的链接,您将能够看到 AWS SSO 在用户、权限集和账户之间的映射: AWS SSO 用户页面 AWS SSO 权限集 Note that the permissions sets tab has the following explanation:请注意,权限集选项卡具有以下说明:

Permission sets define the level of access that assigned users and groups have to this AWS account.权限集定义分配的用户和组对此 AWS 账户的访问级别。 The sets are stored in AWS SSO and appear in this account as IAM roles.这些集存储在 AWS SSO 中并作为 IAM 角色出现在此账户中。 You can update any of the permission sets associated with this AWS account to reapply or reset your permissions policies in IAM.您可以更新与此 AWS 账户关联的任何权限集,以在 IAM 中重新应用或重置您的权限策略。

AWS SSO 账户

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM