When using OneLogin Amazon Web Services (AWS) Multi-Account roles, users may encounter an authorization error when attempting to assume a role.
This issue may occur after adding a SAML attribute such as:
https://aws.amazon.com/SAML/Attributes/PrincipalTag:Username
This issue is typically caused by one or more of the following:
Important:
AWS SAML configuration is strictly case-sensitive, including protocol values and attribute names. Even small differences (e.g., Http vs http) can result in authorization failures.
Follow these steps to resolve the issue:
sts:AssumeRoleWithSAML
https, http, etc.)© 2026 ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center