- Admin permissions in AWS to create the identity provider and the roles.
- An Okta account at Okta (https://www.okta.com)
- Permission to access to Trino
-
Sign in to the Okta Admin dashboard:
https://<company domain name>-admin.okta.com/admin/apps/active -
Select
Browse App Catalogand search forAWS Account Federation.
-
Change
Your AWS Login URLto the appropriate URL, e.g.https://console.aws.amazon.com/console/home?region=us-west-2.
-
Click
Next. -
Select
SAML 2.0asSign on methods. ClickView Setup Instructions, a new window with setup instructions will be popped up.
-
Follow
CONNECT OKTA TO A SINGLE AWS INSTANCEto setup SAML with Okta.
-
Fail to login to AWS by clicking
AWS Account Federation.One possible reason is user is not assigned SAML roles. Go to
Assignmentstab in applicationAWS Account Federation. Click the pencil icon to edit user assignment. Ensure correct role is selected forSAML User Roles. If noRoleorSAML User Rolesis seen, checkProvisioningtab to ensureCreate UsersandUpdate User Attributesare enabled. -
No
SAMLResponsefield in the SAML Assertion response returned from Okta when using Trino ODBC driver.Go to
Sign Ontab in applicationAWS Account Federation. Scroll down to the bottom. CheckAuthentication policyunder sectionUser authentication. Make sure it isPassword only.



