AWS SSO provides single sign-on capabilities for users accessing AWS services. AWS SSO works by requesting a token from an authentication provider, such as SAML, and then providing the token to the AWS SSO service.

The AWS SSO service then uses the token to sign into AWS services on behalf of the user.

PRO TIP: No, AWS SSO is not SAML. SAML is a separate protocol for federated authentication.

While AWS SSO is compatible with SAML, it is not a SAML authentication provider. Therefore, AWS SSO cannot provide full SAML authentication capabilities.

For example, AWS SSO cannot create or manage SAML assertions.

