amazon-web-servicessingle-sign-onscim

How to retrieve groups for a specific user using the AWS SSO SCIM API?


I am trying to use the AWS SSO SCIM API in order to retrieve the AWS SSO groups for a particular user.

Looking at the documentation https://docs.aws.amazon.com/singlesignon/latest/developerguide/listgroups.html

It mentions the following

Also, at https://docs.aws.amazon.com/singlesignon/latest/developerguide/limitations.html next to the members attribute it mentions that it is supported, but cannot be read in a response.

I have been playing with the API but could not get any group info for a user regardless of the combination of the parameters.

Based on the above, I conclude that the API does not support retrieving group data for a user. Would you agree?


Solution

  • As @ZollnerdMSFT recommended, I raised an AWS support request. AWS support responded that the AWS SSO SCIM API does not support retrieving the groups associated with a user. They have submitted this as a feature request internally, however, cannot provide an estimate as to when it will be implemented.