single-sign-onamazon-cognitosamlservice-provideridp

How to add ForceAuthn flag on AWS cognito


I'm using AWS cognito as SP while using SAML with other Idps. I want for specific customer to use ForceAuthn to enforce login in every authentication. How can I do that with AWS cognito? And could it be set for specific integrations into the user pool or have to be set for all of them?

Till now I checked in the documentation and support center. I didn't found option to do that, I saw that 3 months ago they updated other user that it is not supported yet, but hope they added it or there's a work around

Thanks!


Solution

  • Unfortunately ForceAuthn is not currently supported within AWS Cognito. A post with a similar question is on the AWS forum re:post (https://repost.aws/questions/QUeZJlCYyFR8uwhYH10kEYKg/customise-saml-request-to-set-forceauthn-flag)