You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于AWS Cognito与AD FS的Web应用认证配置问题求助

配置AD FS与Cognito用户池对接的分步指引及问题排查

Hey there, let's walk through getting your AD FS setup working with Cognito properly—this is a super common enterprise integration, and I’ve debugged my share of misconfigurations here. Let’s break this down step by step, plus hit the most frequent pain points you might be hitting.

一、先搞定Cognito用户池的SAML身份提供商配置

This is the foundation—get this wrong, and the rest won’t fall into place:

  • Log into your AWS Console, navigate to your Cognito User Pool, go to the Identity Providers tab, and select the SAML option.
  • Upload your AD FS server’s metadata.xml (you can grab this directly from your AD FS instance at https://<your-ad-fs-domain>/FederationMetadata/2007-06/FederationMetadata.xml).
  • Property Mapping is non-negotiable—this is where 90% of folks trip up. Map the SAML claims from AD FS to Cognito’s standard user attributes:
    • Map AD FS’s http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress → Cognito’s email
    • Map AD FS’s http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname → Cognito’s username
    • Make sure to check the box Use this attribute for authentication for each mapped field.
  • Save the provider, then copy the Cognito SAML Metadata URL from the provider details page—you’ll need this for the AD FS side.

二、配置AD FS的依赖方信任

Now let’s point AD FS at your Cognito setup:

  1. Open the AD FS Management Console, right-click Relying Party Trusts → Add Relying Party Trust.
  2. Choose Import data about the relying party from a file or URL, paste the Cognito metadata URL you copied earlier, then click Next.
  3. Give the trust a clear name (like Cognito-YourEnterpriseApp), then click Next.
  4. Select Permit all users to access this relying party, then finish the initial setup.
  5. Configure Claim Rules—another critical step:
    • Right-click the new relying party trust → Edit Claim Rules.
    • Add a rule with the template Send LDAP Attributes as Claims:
      • Name it something like Map AD Attributes to Claims
      • Select Active Directory as the attribute store
      • Map these pairs:
        • LDAP Attribute: E-Mail-Addresses → Outgoing Claim Type: E-Mail Address
        • LDAP Attribute: SAM-Account-Name → Outgoing Claim Type: Windows Account Name
    • Add a second rule with the template Transform an Incoming Claim:
      • Name it Convert Windows Account Name to Name ID
      • Incoming claim type: Windows Account Name
      • Outgoing claim type: Name ID
      • Outgoing Name ID format: Persistent Identifier (this matches Cognito’s default expectation)
      • Check Pass through all claim values

三、Troubleshooting Common Issues

If you’re still hitting roadblocks, let’s rule out the usual suspects:

  • Metadata Sync Problems: Make sure your AD FS server can reach the Cognito metadata URL (no firewall/network restrictions blocking it). If you updated AD FS settings, re-upload its metadata to Cognito—stale metadata breaks everything.
  • Missing SAML Claims: Use a tool like the SAML Tracer browser extension to capture the SAML response during login. Check if the claims you mapped (email, username) are actually present in the response. If not, double-check your AD FS claim rules.
  • Cognito App Client Setup: Ensure your Cognito App Client has the SAML identity provider enabled. Go to App Clients → Hosted UI Settings and add your SAML provider to the list of Identity Providers.
  • Endpoint Misconfiguration: Verify that the relying party trust in AD FS has the correct assertion consumer service URL—it should be https://<your-user-pool-domain>/saml2/idpresponse, which should auto-import from Cognito’s metadata, but you can manually add it if needed.
  • Name ID Format Mismatch: Cognito expects the Name ID format to be urn:oasis:names:tc:SAML:2.0:nameid-format:persistent by default. Confirm your AD FS claim rule for Name ID uses this format.

四、Test the Flow

Once everything’s configured, test the login:

  • Navigate to your Cognito Hosted UI login URL: https://<your-user-pool-domain>/login?client_id=<your-app-client-id>&response_type=code&scope=email+openid&redirect_uri=<your-callback-url>
  • Select your AD FS identity provider, enter your AD credentials, and check if you’re successfully redirected back to your app with a valid user session.

内容的提问来源于stack exchange,提问作者bteres

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 09:23:05