/
AWS - Hidden SSO configurations

AWS - Hidden SSO configurations

AWS Organization App is the Parent App to AWS apps in Zilla.

When we sync AWS Organization App with Discover Child Apps as Yes, It automatically discovers all the member AWS accounts of the AWS Organization and creates respective AWS apps in Zilla.

It also adds the below configurations to these discovered child AWS apps.

  1. Zilla IAM Reader Role Arn (Visible)

  2. Zilla SSO Master Role Arn (Hidden)

  3. SSO Instance Arn (Hidden)

  4. SSO Identity Store ID (Hidden)

  5. Account ID (Hidden)

  6. SSO Region (Hidden)

The first configuration (i.e Zilla IAM Reader Role Arn) is only visible configuration in AWS child Apps. All other configurations are required for SSO sync and are hidden.

User Should not edit the configurations of the AWS Child Apps manually.

If User manually edits the visible configurations of the AWS Child App (i.e. Zilla IAM Reader Role Arn, Sync frequency, enable/disable sync), then it will remove the hidden SSO configurations of this child app. And after syncing this AWS app, the SSO accounts from this app will get marked deleted as the SSO configurations are missing.

To Resolve this scenario,

After manually editing the configurations, do not sync the AWS apps immediately. First sync its Parent AWS Organization App with “Discover child Apps” set to Yes. This will discover the child AWS apps again and will add the SSO configurations to them. If you set the “Auto Sync AWS child apps” to Yes, the child AWS apps will get sync automatically. Now the SSO accounts will get synced again in the AWS child apps

Related content

AWS Organization - Create an IAM Role for SSO Users, Groups and Permission Set
AWS Organization - Create an IAM Role for SSO Users, Groups and Permission Set
More like this
AWS CloudFormation For Creating Zilla-SSO-Reader-Role
AWS CloudFormation For Creating Zilla-SSO-Reader-Role
More like this
AWS - Create an IAM Role for IAM Users, Groups, Roles and Resources
AWS - Create an IAM Role for IAM Users, Groups, Roles and Resources
Read with this
Amazon Web Services
Amazon Web Services
More like this
AWS Organization - AWS CloudFormation For Creating Zilla-IAM-Reader-Role In Member Accounts
AWS Organization - AWS CloudFormation For Creating Zilla-IAM-Reader-Role In Member Accounts
Read with this
AWS Organization - API Integration
AWS Organization - API Integration
More like this