Hi William,
thanks for the response. I've had a quick look over the document and it does look simple.
I am however not sure that it meets my requirements. I have multiple AWS accounts which I want to allow a user to SSO into. Your instructions looks to only provide access to a single account.
In my original request I was trying to dynamically create the RoleEntitlement attribute based on the groups a user was a member of. Each group was for a different AWS account.
Looking at the instructions, what would happen if I set Multivalued as an attribute option? Would I be able to define multiple Entitlements for a user? Do you think would be accepted by AWS?
Thanks,
Mark