Home icon

Enabling single sign-on for AWS Transform with Okta Workforce Identity

Migration and Modernization Blog



This article explains how to configure Okta Workforce Identity as a single sign-on provider for AWS Transform, enabling enterprise users to authenticate with existing corporate credentials and access controls.

  • Create an OIDC Web Application in Okta and configure the issuer to use Okta URL instead of Dynamic
  • Set up a custom Authorization Server with the transform:read_write scope and bind it to the AWS Transform application
  • Add an Access Policy to control which applications can request tokens from the Authorization Server
  • Configure the AWS Transform profile with Okta's Issuer URL, Client ID, and Client Secret
  • Register the AWS Transform callback URL as a sign-in redirect URI in the Okta application
  • Assign users or groups in Okta to control who can access AWS Transform
  • Okta access policies including MFA, network zones, and device trust apply automatically to Transform logins

Integrating Okta with AWS Transform ensures enterprise migration programs operate under consistent identity governance and security policies across the organization.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Sep 3
2026
Enabling single sign-on for AWS Transform with Microsoft Entra ID
Mar 18
2025
Enable single-sign-on for Amazon WorkMail with IAM Identity Center and Okta Universal Directory
Aug 11
2025
Deploy Okta as a custom identity provider for AWS Transfer Family
May 2
2025
Integrate multiple identity providers with AWS IAM Identity Center using Okta

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.