Azure Web App托管标识至AWS非交互式SSO认证技术问询
Got it, let's break down exactly how to get your Azure Web App's managed identity to do non-interactive SSO to AWS using client credentials—building on your already working interactive SSO setup. Here's a step-by-step guide that's actionable right away:
Your Web App's managed identity is just an Azure AD service principal under the hood, so we need to give it application-level permissions to access AWS:
- Head to the Azure Portal, navigate to your Web App, go to Identity > System assigned (or User assigned if that's what you're using), and copy the Client ID of the managed identity.
- Next, go to Azure AD > Enterprise applications, search for that Client ID to find the corresponding service principal.
- Go to Permissions > Add a permission, then select the AWS enterprise application you already set up for interactive SSO.
- Choose Application permissions (not delegated—since this is non-interactive, we're using client credentials, not a user's context) and select the appropriate permissions for your use case.
- Critical step: Click Grant admin consent for [your tenant]—without this, the managed identity won't be able to fetch tokens.
Your existing IAM role for interactive SSO is set up to trust Azure AD users, so we need to modify it to also trust your Azure AD managed identity:
- Log into the AWS Console, go to IAM, and find the role you're using for SSO (or create a new dedicated role for the Web App if you prefer).
- Go to Trust relationships > Edit trust policy.
- Update the policy to include a condition that allows your managed identity's Client ID to assume the role via SAML. Here's an example:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Federated": "arn:aws:iam::YOUR_AWS_ACCOUNT_ID:saml-provider/YOUR_AZURE_AD_IDP_NAME" }, "Action": "sts:AssumeRoleWithSAML", "Condition": { "StringEquals": { "SAML:aud": "https://signin.aws.amazon.com/saml", "SAML:sub": "YOUR_AZURE_AD_MANAGED_IDENTITY_CLIENT_ID" } } } ] }
- Replace placeholders with your actual AWS account ID, Azure AD IDP name, and managed identity Client ID. This ensures only your specific Web App identity can assume this role.
We'll use the managed identity to fetch a SAML assertion, then use that to get temporary AWS credentials via STS. Here's how to do it with common SDKs:
Example: C# with Azure.Identity and AWS SDK
This uses Azure's DefaultAzureCredential to automatically use the Web App's managed identity, no hardcoded secrets needed:
using Azure.Identity; using Amazon.SecurityToken; using Amazon.SecurityToken.Model; using Amazon.S3; // Fetch SAML assertion using the managed identity var azureCredential = new DefaultAzureCredential(); var tokenContext = new TokenRequestContext(new[] { "https://signin.aws.amazon.com/saml" }); var samlToken = await azureCredential.GetTokenAsync(tokenContext); string samlAssertion = samlToken.Token; // Assume the AWS IAM role using the SAML assertion var stsClient = new AmazonSecurityTokenServiceClient(); var assumeRoleRequest = new AssumeRoleWithSAMLRequest { RoleArn = "arn:aws:iam::YOUR_AWS_ACCOUNT_ID:role/YOUR_TARGET_IAM_ROLE", PrincipalArn = "arn:aws:iam::YOUR_AWS_ACCOUNT_ID:saml-provider/YOUR_AZURE_AD_IDP_NAME", SAMLAssertion = samlAssertion }; var stsResponse = await stsClient.AssumeRoleWithSAMLAsync(assumeRoleRequest); // Use temporary credentials to interact with AWS services var awsSessionCreds = new SessionAWSCredentials( stsResponse.Credentials.AccessKeyId, stsResponse.Credentials.SecretAccessKey, stsResponse.Credentials.SessionToken); // Example: Initialize an S3 client with the temporary credentials var s3Client = new AmazonS3Client(awsSessionCreds); var buckets = await s3Client.ListBucketsAsync();
Alternative: Use OIDC Instead of SAML
If you'd prefer to use OAuth2/JWT instead of SAML, you can configure Azure AD as an OIDC identity provider in AWS IAM, then use AssumeRoleWithWebIdentity instead of AssumeRoleWithSAML. This is a good option if you're working with modern AWS services that support OIDC natively.
- Check Azure AD's Audit logs to confirm the managed identity is successfully fetching SAML tokens.
- Look at AWS CloudTrail logs to verify the
AssumeRoleWithSAMLcall is succeeding (or troubleshoot why it's failing). - If you hit permission errors, double-check:
- Admin consent was granted for the Azure AD application permissions.
- The IAM role's trust policy correctly references the managed identity's Client ID.
- The SAML audience (
SAML:aud) matcheshttps://signin.aws.amazon.com/saml.
内容的提问来源于stack exchange,提问作者Jeff

