1. Navigate to AWS IAM identify center.

  2. Navigate to Users side menu. Create a user with the email address who needs an access to Atatus.

  3. Navigate to Applications -> Customer Managed -> Add Application

    Preference: Select "I have an application I want to set up"
    Application Type: SAML 2.0

then click on Next button.

4. In Configure application page, enter the following details:

    Display name: Atatus
    Application metadata: Copy and paste the acs url from Atatus single sign-on page
    Audience: Copy and paste Atatus account id.

then click on Submit button.

AWS Identity Center Configurations

5. Click on Actions -> Edit attribute mappings inside the created application.

6. In Attribute mappings page, enter details like below table and image:

User Attribute in application Maps to this string value or user attribute in IAM Identity Center Format
Subject ${user:subject} unspecified
firstName ${user:givenName} unspecified
lastName ${user:familyName} unspecified
email ${user.email} unspecified

AWS Identity Center Attributes

7. Click on Save changes.

8. Now click on Actions -> Edit configuration -> Download the IAM Identity Center SAML metadata file.

9. In Atatus Single Sign-on settings page, Upload the SAML metadata file.