Enabling single sign-on for AWS Transform with Okta Workforce Identity
Migration and Modernization Blog
This article explains how to configure Okta Workforce Identity as a single sign-on provider for AWS Transform, enabling enterprise users to authenticate with existing corporate credentials and access controls.
- Create an OIDC Web Application in Okta and configure the issuer to use Okta URL instead of Dynamic
- Set up a custom Authorization Server with the transform:read_write scope and bind it to the AWS Transform application
- Add an Access Policy to control which applications can request tokens from the Authorization Server
- Configure the AWS Transform profile with Okta's Issuer URL, Client ID, and Client Secret
- Register the AWS Transform callback URL as a sign-in redirect URI in the Okta application
- Assign users or groups in Okta to control who can access AWS Transform
- Okta access policies including MFA, network zones, and device trust apply automatically to Transform logins
Integrating Okta with AWS Transform ensures enterprise migration programs operate under consistent identity governance and security policies across the organization.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
2026
2025
2025
2025
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.