Skip to content

Update Workspace Authentication

managedgrafana_update_workspace_authentication R Documentation

Use this operation to define the identity provider (IdP) that this workspace authenticates users from, using SAML


Use this operation to define the identity provider (IdP) that this workspace authenticates users from, using SAML. You can also map SAML assertion attributes to workspace user information and define which groups in the assertion attribute are to have the Admin and Editor roles in the workspace.

Changes to the authentication method for a workspace may take a few minutes to take effect.


  samlConfiguration, workspaceId)



[required] Specifies whether this workspace uses SAML 2.0, IAM Identity Center, or both to authenticate users for using the Grafana console within a workspace. For more information, see User authentication in Amazon Managed Grafana.


If the workspace uses SAML, use this structure to map SAML assertion attributes to workspace user information and define which groups in the assertion attribute are to have the Admin and Editor roles in the workspace.


[required] The ID of the workspace to update the authentication for.


A list with the following syntax:

  authentication = list(
    awsSso = list(
      ssoClientId = "string"
    providers = list(
    saml = list(
      configuration = list(
        allowedOrganizations = list(
        assertionAttributes = list(
          email = "string",
          groups = "string",
          login = "string",
          name = "string",
          org = "string",
          role = "string"
        idpMetadata = list(
          url = "string",
          xml = "string"
        loginValidityDuration = 123,
        roleValues = list(
          admin = list(
          editor = list(

Request syntax

  authenticationProviders = list(
  samlConfiguration = list(
    allowedOrganizations = list(
    assertionAttributes = list(
      email = "string",
      groups = "string",
      login = "string",
      name = "string",
      org = "string",
      role = "string"
    idpMetadata = list(
      url = "string",
      xml = "string"
    loginValidityDuration = 123,
    roleValues = list(
      admin = list(
      editor = list(
  workspaceId = "string"