Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
[ad_1]
Amazon QuickSight is a scalable, serverless, embeddable, machine studying (ML)-powered enterprise intelligence (BI) service constructed for the cloud that helps id federation in each Normal and Enterprise editions. Organizations are working in the direction of centralizing their id and entry technique throughout all of their functions, together with on-premises, third-party, and functions on AWS. Many organizations use Ping One to regulate and handle consumer authentication and authorization centrally. In case your group makes use of Ping One for cloud functions, you’ll be able to allow federation to your entire QuickSight accounts without having to create and handle customers in QuickSight. This authorizes customers to entry QuickSight property—analyses, dashboards, folders, and datasets—via centrally managed Ping One.
On this submit, we undergo the steps to configure federated single sign-on (SSO) between a Ping One occasion and a QuickSight account. We display registering an SSO software in Ping One, creating teams, and mapping to an AWS Identification and Entry Administration (IAM) position that interprets to QuickSight consumer license varieties (admin, writer, and reader). These QuickSight roles symbolize three completely different personas supported in QuickSight. Directors can publish the QuickSight app in Ping One to allow customers to carry out SSO to QuickSight utilizing their Ping credentials.
To finish this walkthrough, it’s essential to have the next conditions:
The walkthrough consists of the next steps:
To create teams in Ping One, full the next steps:
QuickSightReaders
.QuickSightAdmins
and QuickSightAuthors
.To configure the mixing of an AWS software in Ping One, you must add AWS to your listing of managed software program as a service (SaaS) apps.
SessionDuration
.QuickSightAdmins
, QuickSightAuthors
, and QuickSightReaders
teams you created.You employ this within the subsequent step.
To configure Ping One as your SAML IdP, full the next steps:
PingOne
.On this step, you create an IAM coverage to map three completely different roles with permissions in QuickSight.
Use the next steps to arrange QuickSightUserCreationPolicy
. This coverage grants privileges in QuickSight to the federated consumer primarily based on the assigned teams in Ping One.
{
"Model": "2012-10-17",
"Assertion": [
{
"Sid": "VisualEditor0",
"Effect": "Allow",
"Action": "quicksight:CreateAdmin",
"Resource": "*",
"Condition": {
"StringEquals": {
"aws:PrincipalTag/user-role": "QuickSightAdmins"
}
}
},
{
"Sid": "VisualEditor1",
"Effect": "Allow",
"Action": "quicksight:CreateUser",
"Resource": "*",
"Condition": {
"StringEquals": {
"aws:PrincipalTag/user-role": "QuickSightAuthors"
}
}
},
{
"Sid": "VisualEditor2",
"Effect": "Allow",
"Action": "quicksight:CreateReader",
"Resource": "*",
"Condition": {
"StringEquals": {
"aws:PrincipalTag/user-role": "QuickSightReaders"
}
}
}
]
}
QuickSightUserCreationPolicy
.Subsequent, create the position that Ping One customers assume when federating into QuickSight. Use the next steps to arrange the federated position:
https://signin.aws.amazon.com/saml
.QuickSightUserCreationPolicy
IAM coverage you created within the earlier step.QSPingOneFederationRole
.QSPingOneFederationRole
position you created to open the position’s properties.https://signin.aws.amazon.com/saml
is current.To configure your AWS software, full the next steps:
https://quicksight.aws.amazon.com/
.Attribute Identify | Worth |
saml_subject |
Username |
https://aws.amazon.com/SAML/Attributes/RoleSessionName |
Username |
https://aws.amazon.com/SAML/Attributes/Function |
‘arn:aws:iam::xxxxxxxxxx:position/QSPingOneFederationRole, arn:aws:iam::xxxxxxxxxx:saml-provider/PingOne’ |
https://aws.amazon.com/SAML/Attributes/PrincipalTag:user-role |
consumer.memberOfGroupNames[0] |
https://aws.amazon.com/SAML/Attributes/PrincipalTag:user-role
for the attribute identify and use the corresponding worth from the desk for the expression.QuickSightAdmins
, QuicksightAuthors
, and QuickSightReaders
), you’ll be able to add all the suitable position names as follows:
The format of the expression is the position ARN (copied within the position creation step) adopted by the IdP ARN (copied within the IdP creation step) separated by a comma.
On this part, you check your Ping One SSO configuration by utilizing a Microsoft software.
Observe within the following screenshot that the consumer identify on the prime of the web page exhibits because the Ping One federated consumer.
This submit supplied step-by-step directions to configure federated SSO between Ping One and the QuickSight console. We additionally mentioned create insurance policies and roles in IAM and map teams in Ping One to IAM roles for safe entry to the QuickSight console.
For extra discussions and assist getting solutions to your questions, try the QuickSight Group.
Srikanth Baheti is a Specialised World Large Sr. Answer Architect for Amazon QuickSight. He began his profession as a guide and labored for a number of personal and authorities organizations. Later he labored for PerkinElmer Well being and Sciences & eResearch Expertise Inc, the place he was accountable for designing and creating excessive site visitors net functions, extremely scalable and maintainable knowledge pipelines for reporting platforms utilizing AWS companies and Serverless computing.
Raji Sivasubramaniam is a Sr. Options Architect at AWS, specializing in Analytics. Raji is specialised in architecting end-to-end Enterprise Information Administration, Enterprise Intelligence and Analytics options for Fortune 500 and Fortune 100 corporations throughout the globe. She has in-depth expertise in built-in healthcare knowledge and analytics with huge number of healthcare datasets together with managed market, doctor concentrating on and affected person analytics.
Raj Jayaraman is a Senior Specialist Options Architect for Amazon QuickSight. Raj focuses on serving to prospects develop pattern dashboards, embed analytics and undertake BI design patterns and finest practices.
[ad_2]