Enabling single sign-on for AWS Transform with Microsoft Entra ID
Migration and Modernization Blog
This article provides a complete guide to enabling single sign-on for AWS Transform with Microsoft Entra ID using OpenID Connect protocol.
- Register an application in Entra ID and configure OAuth 2.0 scope transform:read_write for AWS Transform access
- Set access token version to v2.0 and create a client secret for authentication between systems
- Configure redirect URI in Entra ID to complete the OIDC authorization code flow
- Enable AWS Transform in AWS Management Console with Entra ID credentials (Client ID, Client Secret, Issuer URL)
- Assign users or groups in Entra ID to control who can authenticate to AWS Transform
- Existing conditional access policies, MFA requirements, and device compliance checks apply automatically
- All AWS Transform activity is logged in CloudTrail with Entra oid claim for audit correlation
Connecting AWS Transform to Microsoft Entra ID enables enterprise-scale migrations with centralized identity management, consistent security policies, and unified audit trails across both systems.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Sep 3
2026
2026
Enabling single sign-on for AWS Transform with Okta Workforce Identity
Feb 25
2025
2025
Enhancing Security with AWS Verified Access and Microsoft Entra ID Integration
Jan 23
2024
2024
Automating OpenID Connect-Based AWS IAM Web Identity Roles with Microsoft Entra ID
Jun 3
2025
2025
Implementing just-in-time privileged access to AWS with Microsoft Entra and AWS IAM Identity Center
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.