Hi,
I am a bit confused about this Integration. Say, here is what I have and my client is requesting a seamless integration with minimal code and maintenance.
1 All the Identities who will be accessing Quick Sight are in Okta so it SAML federated Identities.
2 We would like that all users who use the Okta -QS App should be auto registered with Quicksight using the email address which they used to Authenticate.
No, you need to have the access key - you need to create an AWS user with specific permissions so Okta can dynamically fetch a list of available roles from your accounts. This makes assigning users and groups to specific AWS roles easy and secure for administrators.
The access key is associated with an IAM user that has permissions to assume the necessary IAM roles
This enables Okta to assume the appropriate roles for Quick Sight federation
A lot of clients may not allow the creation of access keys. I understand that the users who are part of an OKTA group have to pre-provisioned in Quick Sight. Is this the place where a scheduled Lambda can read from the Okta group and populate Quick Sight ?