Skip to content

CreateSAMLProvider

AWS

CreateSAMLProvider

service: AWS - IAM
techniques:

Event

Creates a SAML provider from metadata containing issuer and signing-certificate information. Registration alone creates neither an IAM user nor a role session. A role must trust the provider and the presented token or assertion must satisfy validation and trust conditions.

Security Context

Unauthorized federation configuration can prepare an alternative access path, contextually matching T1556 and T1484.002. Approved identity-provider onboarding is normal. Establish control of the provider and usable role trust before claiming persistence or elevated access.

Log Source

AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: CreateSAMLProvider. Check errorCode and errorMessage before treating an attempt as successful; responseElements: null alone does not indicate failure. Include IAM global-service events in collection.

Key Fields

FieldInvestigation value
requestParameters.nameProvider name; not proof of ownership or malicious intent.
requestParameters.sAMLMetadataDocumentMetadata may not be available in the record; inspect secured configuration history.
responseElements.sAMLProviderArnProvider ARN for role-trust correlation.
eventTime, recipientAccountId, eventID, requestIDTimeline, account, and correlation identifiers.

What to Investigate

  1. Confirm the outcome and match the caller, target, and timing to an approved workflow. Review failed attempts separately.
  2. Recover the approved metadata securely and compare issuer, signing certificates, endpoints, and validity periods.
  3. Find roles trusting the provider, including UpdateAssumeRolePolicy changes. Review audience, subject, and other applicable conditions.
  4. Correlate AssumeRoleWithSAML and subsequent role activity. Provider creation is not evidence of successful federation.

Sample Event

Synthetic scenario. Draco registers DracoExternalIdP with a placeholder for metadata. The sample does not show the metadata, software used to generate it, role trust, or any successful assertion exchange.

Exact CloudTrail nesting, field presence, redaction, and timestamp formatting remain unverified against captured logs. Credential/token placeholders and metadata placeholders are illustrative, not usable credentials or complete provider metadata.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-16T00:51:42Z",
"eventSource": "iam.amazonaws.com",
"eventName": "CreateSAMLProvider",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"name": "DracoExternalIdP",
"sAMLMetadataDocument": "HIDDEN_DUE_TO_SECURITY_REASONS"
},
"responseElements": {
"sAMLProviderArn": "arn:aws:iam::555123456789:saml-provider/DracoExternalIdP"
},
"requestID": "90000000-0000-4000-8000-000010011100",
"eventID": "90000000-0000-4000-8000-000010011101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation Defense Impairment

Techniques:
  • T1556 — Modify Authentication Process — Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SA...
  • T1484.002 — Trust Modification — Adversaries may add new domain trusts, modify the properties of existing domain trusts, or otherwise change the configuration of trust relationships between domains and tenants to evade defenses and/or elevate privileges.Trust details, such as whether or not user identities are federated, allow a...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.