{"id":89844,"date":"2023-06-07T13:03:05","date_gmt":"2023-06-07T17:03:05","guid":{"rendered":"https:\/\/jumpcloud.com\/?post_type=support&p=89844"},"modified":"2024-04-08T18:11:52","modified_gmt":"2024-04-08T22:11:52","slug":"integrate-with-aws-govcloud-us","status":"publish","type":"support","link":"https:\/\/jumpcloud.com\/support\/integrate-with-aws-govcloud-us","title":{"rendered":"Integrate with AWS GovCloud (US)"},"content":{"rendered":"\n
Use JumpCloud SAML Single Sign On (SSO) to give your users convenient but secure access to all their web applications with a single set of credentials. <\/p>\n\n\n\n
Read this article to learn how to configure the AWS GovCloud connector. <\/p>\n\n\n\n
Prerequisites<\/strong><\/p>\n\n\n\n Find your account number by going to the main AWS console, go to\u00a0All Services<\/strong>, under\u00a0Security, Identity & Compliance<\/strong>\u00a0select\u00a0IAM<\/strong>. It will be embedded in the IAM users sign-in link:\u00a0https:\/\/YOUR_AWS_ACCOUNT_NUMBER.signin.aws.amazon.com\/console<\/kbd>.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n Important Considerations<\/strong><\/p>\n\n\n\n If this is a Bookmark Application, enter your sign-in URL in the Bookmark URL<\/strong> field.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n The SSO IdP URL<\/strong> is not editable after the application is created. You will have to delete and recreate the connector if you need to edit this field at a later time.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n Metadata can also be downloaded from the Configured Applications<\/strong> list. Search for and select the application in the list and then click Export Metadata<\/strong> in the top right corner of the window.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n Users are implicitly denied access to applications. After you connect an application to JumpCloud, you need to authorize user access to that application. You can authorize user access from the Application Configuration<\/strong> panel or from the Groups Configuration<\/strong> panel. <\/p>\n\n\n\n To learn how to authorize user access from the Groups Configuration<\/strong> panel, see Authorize Users to an SSO Application<\/a>.<\/p>\n\n\n\n This varies by SP.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n These are steps for removing the integration in JumpCloud. Consult your SP’s documentation for any additional steps needed to remove the integration in the SP. Failure to remove the integration successfully for both the SP and JumpCloud may result in users losing access to the application.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n\n
<\/p><\/div>
\n
Creating a new JumpCloud Application Integration<\/strong><\/h2>\n\n\n\n
\n
<\/p><\/div>
\n
<\/p><\/div>
\n
\n
Configuring the SSO Integration<\/strong><\/h2>\n\n\n\n
To configure JumpCloud<\/strong><\/h3>\n\n\n\n
\n
\n
Download the JumpCloud metadata<\/strong> file<\/strong><\/h4>\n\n\n\n
\n
<\/p><\/div>
To configure AWS GovCloud (US)<\/strong><\/h3>\n\n\n\n
\n
Authorizing User SSO Access<\/strong><\/h2>\n\n\n\n
To authorize user access from the Application Configuration panel<\/strong><\/h3>\n\n\n\n
\n
Validating SSO user authentication workflow(s)<\/strong><\/h2>\n\n\n\n
IdP-initiated<\/strong> user workflow<\/strong><\/h3>\n\n\n\n
\n
SP-initiated<\/strong> user workflow<\/strong><\/h3>\n\n\n\n
\n
<\/p><\/div>
\n
Removing the SSO Integration<\/strong><\/h2>\n\n\n\n
<\/p><\/div>
To deactivate<\/strong><\/strong> the SSO Integration<\/strong><\/h3>\n\n\n\n