SSO on Pump
If your AWS Organization uses SSO through IAM Identity Center (formerly AWS SSO), Pump migrates your SSO configuration to the new Pump-managed organization as part of the onboarding process. This is a guided process with a Pump solutions architect.
Overview
When you join Pump with a pre-existing AWS Organization, Pump provisions a new org and provides you with a delegated administrator account. Your SSO configuration (users, groups, permission sets) is exported from your current org and imported into the new one.
Total time: approximately 30 to 45 minutes on a call with a Pump solutions architect, plus about 5 minutes of preparation beforehand.
Before the call (approximately 5 minutes)
Provide Pump with an email address to use for the root user of the delegated administrator account.
Specify the AWS region where you want SSO enabled.
Pump provisions the new organization with the delegated admin account and SSO enabled in your specified region.
Log in to the delegated admin account using the email you provided. Use the "forgot my password" flow to set a password.
On the call (30 to 45 minutes)
1. Export existing SSO
While screen-sharing, log into your current management account and run an export script in IAM Identity Center. This downloads your current users, groups, and permission sets.
2. Import to new org
Log into the new delegated administrator account and run an import script to upload your users, groups, and permission sets into the new organization.
3. Third-party IdP (if applicable)
If you use a third-party identity provider (Okta, Azure AD, Google Workspace, etc.), create a new SAML or SCIM application that points to the new IAM Identity Center instance.
4. Test
Verify SSO access by logging in through your identity provider and confirming access to your accounts.
After migration
Your SSO works exactly as before. Users log in through the same identity provider, access the same accounts, and have the same permission sets. The only difference is that IAM Identity Center now runs in the Pump-managed organization's delegated admin account instead of your previous management account.
Important notes
IAM Identity Center is managed through the delegated administrator account, not through the PumpCustomerAccess role on the management account. If you need to make changes to SSO configuration after migration (adding users, modifying permission sets), log into the delegated admin account.
Last updated
Was this helpful?

