Amazon prerequisites
Complete the following steps in your Amazon Web Services account.
To set up the Amazon side of the federation
-
Enable outbound web identity federation
Enable outbound web identity federation in your Amazon Web Services account IAM settings. This allows Amazon to issue OIDC tokens that Azure can verify.
In the IAM console, navigate to Account settings and enable Outbound web identity federation. Alternatively, use the Amazon CLI:
aws iam enable-outbound-web-identity-federation -
Note the OIDC issuer URL
After enabling outbound web identity federation, note the Amazon OIDC issuer URL for your account. The URL has the following format:
https://UNIQUE_ID.tokens.sts.global.api.awsYou need this URL when configuring the federated identity credential in Azure.