{"id":3150,"date":"2026-09-29T09:24:44","date_gmt":"2026-09-29T09:24:44","guid":{"rendered":"https:\/\/devsecopsschool.com\/blog\/?p=3150"},"modified":"2026-09-29T09:24:45","modified_gmt":"2026-09-29T09:24:45","slug":"using-memberof-with-aws-client-vpn-and-saml-a-practical-guide","status":"publish","type":"post","link":"http:\/\/devsecopsschool.com\/blog\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\/","title":{"rendered":"Using memberOf with AWS Client VPN and SAML: A Practical Guide"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Using <code>memberOf<\/code> with AWS Client VPN and SAML: A Practical Guide to Group-Based Network Authorization<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When AWS Client VPN is integrated with a SAML 2.0 identity provider, authentication answers one question:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Who is the user?<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">But many organizations need a second level of control:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Which networks should that user be allowed to access?<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">This is where the SAML <strong><code>memberOf<\/code><\/strong> attribute becomes useful.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">AWS Client VPN can receive a user&#8217;s group membership in the SAML assertion and use that information in <strong>Client VPN authorization rules<\/strong>. This allows multiple user groups to authenticate through the same VPN application while receiving different levels of network access. <a href=\"https:\/\/docs.aws.amazon.com\/vpn\/latest\/clientvpn-admin\/federated-authentication.html?utm_source=chatgpt.com\">AWS Documentation<\/a><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">1. What is <code>memberOf<\/code>?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><code>memberOf<\/code> is a SAML attribute that tells AWS Client VPN which identity-provider groups the authenticated user belongs to.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Conceptually, a SAML assertion might contain:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;Attribute Name=\"memberOf\"&gt;\n    &lt;AttributeValue&gt;\n        group-123456\n    &lt;\/AttributeValue&gt;\n    &lt;AttributeValue&gt;\n        group-789012\n    &lt;\/AttributeValue&gt;\n&lt;\/Attribute&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This means:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>User\n \u251c\u2500\u2500 belongs to Group A: group-123456\n \u2514\u2500\u2500 belongs to Group B: group-789012<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">AWS Client VPN can inspect those group values and compare them with its authorization rules.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">AWS specifically requires the attribute name to be:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>memberOf<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The name is <strong>case-sensitive<\/strong> when using SAML group-based authorization. <a href=\"https:\/\/docs.aws.amazon.com\/vpn\/latest\/clientvpn-admin\/federated-authentication.html?utm_source=chatgpt.com\">AWS Documentation<\/a><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">2. Authentication vs Authorization<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">This distinction is the most important part of the design.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Authentication<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Authentication determines whether the user can establish a VPN session.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For SAML authentication:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>User\n  \u2193\nAWS VPN Client\n  \u2193\nSAML Identity Provider\n  \u2193\nUser signs in \/ MFA\n  \u2193\nSAML assertion\n  \u2193\nAWS Client VPN\n  \u2193\nVPN session established<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">AWS Client VPN validates the SAML assertion and, if authentication succeeds, establishes the VPN connection. <a href=\"https:\/\/docs.aws.amazon.com\/vpn\/latest\/clientvpn-admin\/federated-authentication.html?utm_source=chatgpt.com\">AWS Documentation<\/a><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Authorization<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Authorization determines:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>What can the authenticated user reach through that VPN connection?<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">This happens through AWS Client VPN <strong>authorization rules<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Developers\n    \u2193\n10.10.0.0\/16\n\nDatabase Admins\n    \u2193\n10.20.10.0\/24\n\nPlatform Admins\n    \u2193\n10.0.0.0\/8<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">AWS Client VPN authorization rules can associate a destination CIDR with a SAML group. Users who do not have a matching authorization rule do not get access to that network. The default behavior is deny unless access has been explicitly authorized. <a href=\"https:\/\/docs.aws.amazon.com\/vpn\/latest\/clientvpn-admin\/cvpn-working-rules.html?utm_source=chatgpt.com\">AWS Documentation<\/a><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">3. Why <code>memberOf<\/code> is useful<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Consider an organization that has one VPN application assigned to three groups:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Corporate VPN Application\n\n\u251c\u2500\u2500 Developers\n\u251c\u2500\u2500 Database-Admins\n\u2514\u2500\u2500 Platform-Admins<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">All three groups may be permitted to authenticate to the same SAML application.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Without group-based authorization:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>All authenticated users\n        \u2193\nSame VPN access\n        \u2193\nPotentially same networks<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">With <code>memberOf<\/code>:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"> <code>                 SAML Application\n                        \u2502\n        \u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u253c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510\n        \u2502               \u2502               \u2502\n   Developers      DB Admins      Platform Admins\n        \u2502               \u2502               \u2502\n        \u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u253c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518\n                        \u2502\n                  memberOf values\n                        \u2502\n                        \u25bc\n                 AWS Client VPN\n                        \u2502\n                 Authorization Rules\n                 \/          |          \\\n                \/           |           \\\n      App Networks      DB Network     Admin Networks<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">You can therefore reuse one authentication system while applying different network permissions.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">4. Example Scenario<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Suppose an organization has these groups:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>VPN-Developers\nVPN-Database-Admins\nVPN-Platform-Admins<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The corresponding identity-provider group IDs might be:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>VPN-Developers\nGroup ID:\n11111111-aaaa-bbbb-cccc-111111111111\n\nVPN-Database-Admins\nGroup ID:\n22222222-aaaa-bbbb-cccc-222222222222\n\nVPN-Platform-Admins\nGroup ID:\n33333333-aaaa-bbbb-cccc-333333333333<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">A developer&#8217;s SAML assertion could contain:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;Attribute Name=\"memberOf\"&gt;\n    &lt;AttributeValue&gt;\n        11111111-aaaa-bbbb-cccc-111111111111\n    &lt;\/AttributeValue&gt;\n&lt;\/Attribute&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">A platform engineer who belongs to two groups might receive:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;Attribute Name=\"memberOf\"&gt;\n\n    &lt;AttributeValue&gt;\n        11111111-aaaa-bbbb-cccc-111111111111\n    &lt;\/AttributeValue&gt;\n\n    &lt;AttributeValue&gt;\n        33333333-aaaa-bbbb-cccc-333333333333\n    &lt;\/AttributeValue&gt;\n\n&lt;\/Attribute&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">AWS Client VPN evaluates these group values against its authorization rules.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">5. Example Authorization Rules<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Consider this network:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Application VPC\n10.10.0.0\/16\n\nDatabase subnet\n10.10.50.0\/24\n\nManagement subnet\n10.10.100.0\/24<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Authorization could be designed as:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Group<\/th><th>Destination<\/th><th>Access<\/th><\/tr><\/thead><tbody><tr><td>Developers<\/td><td><code>10.10.0.0\/16<\/code><\/td><td>Application network<\/td><\/tr><tr><td>Database Admins<\/td><td><code>10.10.50.0\/24<\/code><\/td><td>Database subnet<\/td><\/tr><tr><td>Platform Admins<\/td><td><code>10.10.100.0\/24<\/code><\/td><td>Management subnet<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">For the Developers group:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Destination network:\n10.10.0.0\/16\n\nGrant access to:\nUsers in a specific access group\n\nAccess Group ID:\n11111111-aaaa-bbbb-cccc-111111111111<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">AWS requires the group ID\/name entered in the authorization rule to match the group information returned in the SAML assertion. <a href=\"https:\/\/docs.aws.amazon.com\/vpn\/latest\/clientvpn-admin\/cvpn-working-rule-authorize-add.html?utm_source=chatgpt.com\">AWS Documentation<\/a><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">6. Example Access Flow<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Suppose Alice is a Developer.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Alice\n  \u2193\nSign in through SAML IdP\n  \u2193\nSAML assertion\n\nmemberOf =\n11111111-aaaa-bbbb-cccc-111111111111\n  \u2193\nAWS Client VPN\n  \u2193\nAuthorization rule lookup\n  \u2193\nDeveloper group matches\n  \u2193\n10.10.0.0\/16 allowed<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Now suppose Bob belongs only to the Database Admin group:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Bob\n  \u2193\nVPN authentication succeeds\n  \u2193\nmemberOf =\n22222222-aaaa-bbbb-cccc-222222222222\n  \u2193\nNo Developer rule matches\n  \u2193\n10.10.0.0\/16 access denied<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">But Bob may have another authorization rule allowing:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>10.10.50.0\/24<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">So the important point is:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">A user may successfully connect to the VPN while still being unable to reach a particular network.<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">AWS demonstrates this behavior directly in its IAM Identity Center + Client VPN guidance: a user outside the authorized group can establish the VPN connection but cannot reach the protected network. <a href=\"https:\/\/aws.amazon.com\/blogs\/security\/authenticate-aws-client-vpn-users-with-aws-single-sign-on\/?utm_source=chatgpt.com\">Amazon Web Services, Inc.<\/a><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">7. IAM Identity Center Example<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">When AWS IAM Identity Center is used as the SAML identity provider, a typical attribute mapping is:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Application attribute<\/th><th>IAM Identity Center value<\/th><th>Format<\/th><\/tr><\/thead><tbody><tr><td><code>Subject<\/code><\/td><td><code>${user:email}<\/code><\/td><td><code>emailAddress<\/code><\/td><\/tr><tr><td><code>memberOf<\/code><\/td><td><code>${user:groups}<\/code><\/td><td><code>unspecified<\/code><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">AWS documents this mapping specifically for AWS Client VPN. Identity Center passes group membership using <strong>group IDs<\/strong>, which are then referenced by Client VPN authorization rules. <a href=\"https:\/\/aws.amazon.com\/blogs\/security\/authenticate-aws-client-vpn-users-with-aws-single-sign-on\/?utm_source=chatgpt.com\">Amazon Web Services, Inc.<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Conceptually:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>IAM Identity Center\n\nUser\n \u251c\u2500\u2500 Developers\n \u2514\u2500\u2500 Platform-Team\n       \u2193\n${user:groups}\n       \u2193\nmemberOf\n       \u2193\nSAML Assertion\n       \u2193\nAWS Client VPN<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">8. Identity Provider vs Client VPN Authorization<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">A common source of confusion is the role of the IAM SAML Identity Provider.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The IAM SAML provider is <strong>not where group access is filtered<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Its job is primarily to establish trust between AWS and the SAML identity provider:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Identity Provider\n       \u2193\nSAML metadata \/ certificates\n       \u2193\nIAM SAML Provider\n       \u2193\nAWS Client VPN<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">It does not provide a configuration such as:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Allow Group A\nDeny Group B<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Instead, the filtering happens here:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SAML IdP\n   \u2193\nmemberOf\n   \u2193\nAWS Client VPN\n   \u2193\nAuthorization Rule\n   \u2193\nDestination CIDR<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">So:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>IAM SAML Provider\n= Trust\n\nmemberOf\n= Group identity information\n\nClient VPN Authorization Rule\n= Network access decision<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">9. Application Assignment vs Network Authorization<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">There are actually two useful levels of group control.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Level 1 \u2014 Application assignment<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Controls:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">Who can use the SAML VPN application?<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>VPN Application\n   \u2193\nAssigned groups:\nDevelopers\nPlatform-Team<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">A user not assigned to the application cannot normally use that application.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Level 2 \u2014 Client VPN authorization<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Controls:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">After authentication, what network can the user reach?<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Developers\n   \u2193\n10.10.0.0\/16\n\nPlatform-Team\n   \u2193\n10.20.0.0\/16<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">These controls complement one another:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Identity Provider\n      \u2502\n      \u2502 Application assignment\n      \u25bc\nCan user authenticate?\n      \u2502\n      \u25bc\nAWS Client VPN\n      \u2502\n      \u2502 Authorization rules\n      \u25bc\nWhich network can user access?<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">10. Multiple Groups Assigned to One SAML Application<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">A very useful scenario is:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>VPN Application\n\u251c\u2500\u2500 Group A\n\u2514\u2500\u2500 Group B<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Both groups can remain assigned to the application.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Suppose only Group A should access:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>10.50.0.0\/16<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Configure:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Authorization Rule\n\nDestination:\n10.50.0.0\/16\n\nAccess Group:\nGroup-A-ID<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The result becomes:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Group A user\nAuthentication     \u2705\nVPN Connection     \u2705\n10.50.0.0\/16       \u2705\n\n\nGroup B user\nAuthentication     \u2705\nVPN Connection     \u2705\n10.50.0.0\/16       \u274c<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This allows organizations to avoid creating a separate VPN or separate SAML application for every network-access group.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">11. Multiple Authorization Rules<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">A single Client VPN endpoint can support multiple group-based authorization rules.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"> <code>                        AWS Client VPN\n                              \u2502\n          \u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u253c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510\n          \u2502                   \u2502                    \u2502\n          \u25bc                   \u25bc                    \u25bc\n     Developers            DB Admins          Platform Admins\n\n    10.10.0.0\/16        10.20.10.0\/24        10.30.0.0\/16<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Rules:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Developers\n\u2192 10.10.0.0\/16\n\nDatabase-Admins\n\u2192 10.20.10.0\/24\n\nPlatform-Admins\n\u2192 10.30.0.0\/16<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">AWS Client VPN treats authorization rules as explicit grants. Traffic without a matching authorization rule is dropped. <a href=\"https:\/\/docs.aws.amazon.com\/vpn\/latest\/clientvpn-admin\/cvpn-working-rules.html?utm_source=chatgpt.com\">AWS Documentation<\/a><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">12. Users Belonging to Multiple Groups<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">A user may belong to several groups:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Alice\n\u251c\u2500\u2500 Developers\n\u251c\u2500\u2500 Platform\n\u2514\u2500\u2500 Database-ReadOnly<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Her SAML assertion could contain multiple <code>memberOf<\/code> values:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;Attribute Name=\"memberOf\"&gt;\n\n    &lt;AttributeValue&gt;group-developers&lt;\/AttributeValue&gt;\n\n    &lt;AttributeValue&gt;group-platform&lt;\/AttributeValue&gt;\n\n    &lt;AttributeValue&gt;group-db-readonly&lt;\/AttributeValue&gt;\n\n&lt;\/Attribute&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Client VPN can then match Alice against every applicable authorization rule.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Her effective network access becomes the combination of the networks granted to those groups.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Developers\n\u2192 10.10.0.0\/16\n\nPlatform\n\u2192 10.20.0.0\/16\n\nDatabase-ReadOnly\n\u2192 10.30.50.0\/24<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Alice could therefore reach all three authorized destinations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is why group membership should be designed carefully: <strong>membership in any authorized group can grant the corresponding network access<\/strong>.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">13. A Common Mistake: &#8220;Allow Access to All Users&#8221;<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Suppose you configure:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Destination:\n10.10.0.0\/16\n\nAllow access to all users:\nTrue<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">and also configure:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Destination:\n10.10.0.0\/16\n\nAccess Group:\nDevelopers<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The group-specific rule does not turn the first rule into a deny rule.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">AWS Client VPN authorization rules <strong>grant access; they do not create explicit deny rules<\/strong>. <a href=\"https:\/\/docs.aws.amazon.com\/vpn\/latest\/clientvpn-admin\/cvpn-working-rules.html?utm_source=chatgpt.com\">AWS Documentation<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Therefore, if your objective is:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">Only Developers should access the network<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">you should avoid an authorization rule that grants the same destination to all users.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Use:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Allow all users: FALSE\n\nAccess group:\nDevelopers<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">14. Route vs Authorization Rule<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Another important concept:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A <strong>route<\/strong> and an <strong>authorization rule<\/strong> solve different problems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A route tells Client VPN:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">Where should packets go?<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">An authorization rule tells Client VPN:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">Which users are allowed to send packets there?<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">You generally need both.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>User\n \u2193\nVPN\n \u2193\nAuthorization Rule\n\"Is this user allowed?\"\n \u2193\nRoute\n\"Where should this packet go?\"\n \u2193\nDestination<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Route:\n10.10.0.0\/16 \u2192 VPC\n\nAuthorization:\nDevelopers \u2192 10.10.0.0\/16<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Having a route without authorization does not automatically grant the user access.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">15. Security Groups Still Matter<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\"><code>memberOf<\/code> does not replace VPC security controls.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The complete path may look like:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SAML authentication\n       \u2193\nmemberOf\n       \u2193\nClient VPN authorization\n       \u2193\nClient VPN route\n       \u2193\nVPC routing\n       \u2193\nSecurity Group\n       \u2193\nApplication \/ EKS \/ Database<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For example, Client VPN might authorize:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Developers \u2192 10.10.0.0\/16<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">but a database security group may still permit only:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>TCP 5432\nfrom approved sources<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Client VPN authorization should therefore be considered <strong>one layer in a defense-in-depth model<\/strong>, not a replacement for security groups.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">16. Example: Private Kubernetes \/ EKS Access<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">A common use case is removing public access to a Kubernetes control plane.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Architecture:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Developer Laptop\n      \u2193\nAWS VPN Client\n      \u2193\nSAML Login\n      \u2193\nIdentity Provider\n      \u2193\nmemberOf\n      \u2193\nAWS Client VPN\n      \u2193\nAuthorization Rule\n      \u2193\nPrivate VPC\n      \u2193\nPrivate Kubernetes API<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Suppose:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Group:\nPlatform-Engineers\n\nDestination:\n10.40.0.0\/16<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Only users whose SAML assertion contains the Platform Engineers group value receive network authorization to the VPC.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">They can then use local tooling such as:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>kubectl get pods<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">without exposing the Kubernetes API publicly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Authentication to Kubernetes itself remains a <strong>separate authorization layer<\/strong>:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>VPN authorization\n= Can reach Kubernetes API\n\nKubernetes\/AWS IAM authorization\n= What can the user do inside Kubernetes<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This distinction is important.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">VPN group access should not be confused with Kubernetes RBAC.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">17. Example: Database Access<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Another useful scenario:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>VPN-Developers\nVPN-DBA<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Rules:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Developers\n\u2192 10.10.0.0\/16\n\nDBA\n\u2192 10.20.50.0\/24<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">A DBA user:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>memberOf = DBA-group-ID<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">may get access to:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>10.20.50.0\/24<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">while a developer does not.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Security groups can further restrict the database to:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>TCP 5432<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">or:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>TCP 3306<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This creates layered controls:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Identity\n\u2192 Group\n\u2192 VPN network authorization\n\u2192 Security Group\n\u2192 Database authentication<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">18. Example: Environment Separation<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">One VPN endpoint could potentially serve several environments:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>VPN-Development\nVPN-Staging\nVPN-Production<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Authorization rules:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>VPN-Development\n\u2192 10.10.0.0\/16\n\nVPN-Staging\n\u2192 10.20.0.0\/16\n\nVPN-Production\n\u2192 10.30.0.0\/16<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">A user belonging only to:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>VPN-Staging<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">can authenticate to the common VPN but receive network authorization only for:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>10.20.0.0\/16<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This is useful when organizations want <strong>one common authentication mechanism<\/strong> while maintaining environment-level segmentation.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">19. Finding the Group ID<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">When IAM Identity Center is the IdP, AWS recommends using the Identity Center <strong>group ID<\/strong>, not merely assuming the friendly group name will be sent.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A group might look like:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Display name:\nVPN-Developers\n\nGroup ID:\n9067e4d8-1234-5678-abcd-123456789abc<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The authorization rule should use:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>9067e4d8-1234-5678-abcd-123456789abc<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">if that is the value returned by the SAML assertion. <a href=\"https:\/\/aws.amazon.com\/blogs\/security\/authenticate-aws-client-vpn-users-with-aws-single-sign-on\/?utm_source=chatgpt.com\">Amazon Web Services, Inc.<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The key rule is:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Use exactly the group value returned in the SAML <code>memberOf<\/code> assertion.<\/strong><\/p>\n<\/blockquote>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">20. How to Verify <code>memberOf<\/code><\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">With IAM Identity Center, AWS documents a handy troubleshooting method.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sign in to the IAM Identity Center user portal and <strong>hold Shift while selecting the SAML VPN application<\/strong>. IAM Identity Center displays the generated SAML assertion, allowing you to inspect the <code>memberOf<\/code> values actually being sent. <a href=\"https:\/\/aws.amazon.com\/blogs\/security\/authenticate-aws-client-vpn-users-with-aws-single-sign-on\/?utm_source=chatgpt.com\">Amazon Web Services, Inc.<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You should see something conceptually similar to:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;Attribute Name=\"memberOf\"&gt;\n\n    &lt;AttributeValue&gt;\n        9067e4d8-1234-5678-abcd-123456789abc\n    &lt;\/AttributeValue&gt;\n\n&lt;\/Attribute&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">That exact value should correspond to:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Client VPN\n\u2192 Authorization Rules\n\u2192 Access Group ID<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">21. Troubleshooting Checklist<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">If authentication succeeds but network access fails, check:<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>Is <code>memberOf<\/code> spelled exactly correctly?<\/li>\n\n\n\n<li>Is it mapped to the user&#8217;s groups in the IdP?<\/li>\n\n\n\n<li>Does the SAML assertion actually contain the expected group ID?<\/li>\n\n\n\n<li>Does the Client VPN authorization rule use that exact ID\/value?<\/li>\n\n\n\n<li>Is there an authorization rule for the required destination CIDR?<\/li>\n\n\n\n<li>Does Client VPN have a route to that destination?<\/li>\n\n\n\n<li>Do VPC route tables allow the path?<\/li>\n\n\n\n<li>Do security groups\/NACLs allow the required traffic?<\/li>\n\n\n\n<li>Is DNS resolution working for private endpoints?<\/li>\n\n\n\n<li>Does the user belong to the expected group?<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">AWS currently limits users to <strong>200 groups for Client VPN group processing<\/strong>; groups beyond that limit are ignored. <a href=\"https:\/\/docs.aws.amazon.com\/vpn\/latest\/clientvpn-admin\/limits.html?utm_source=chatgpt.com\">AWS Documentation<\/a><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">22. Recommended Design Pattern<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">A clean enterprise design looks like:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"> <code>                        Identity Provider\n                               \u2502\n                               \u2502 SAML\n                               \u2502\n                      memberOf = groups\n                               \u2502\n                               \u25bc\n                       AWS Client VPN\n                               \u2502\n                 \u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u253c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510\n                 \u2502             \u2502             \u2502\n            Developers      DB Admins    Platform\n                 \u2502             \u2502             \u2502\n                 \u25bc             \u25bc             \u25bc\n              App VPC       DB subnet    Management<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Use the IdP for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>identity lifecycle<\/li>\n\n\n\n<li>MFA<\/li>\n\n\n\n<li>user\/group membership<\/li>\n\n\n\n<li>SAML authentication<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Use Client VPN for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>destination-level network authorization<\/li>\n\n\n\n<li>group-to-CIDR mapping<\/li>\n\n\n\n<li>VPN connectivity<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Use VPC\/application controls for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>ports<\/li>\n\n\n\n<li>protocols<\/li>\n\n\n\n<li>workload authorization<\/li>\n\n\n\n<li>application permissions<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">23. Key Takeaways<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\"><code>memberOf<\/code> creates the bridge between <strong>identity groups and network authorization<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The overall model is:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>User\n \u2193\nIdentity Provider\n \u2193\nAuthentication\n \u2193\nSAML assertion\n \u2193\nmemberOf = Group IDs\n \u2193\nAWS Client VPN\n \u2193\nAuthorization Rule\n \u2193\nAllowed Destination CIDR<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The IAM SAML provider itself does <strong>not<\/strong> decide which group receives network access. It establishes the trust relationship used for federated authentication.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <strong>Client VPN authorization rule<\/strong> is where the group value carried by <code>memberOf<\/code> is converted into actual network permissions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This allows organizations to maintain <strong>one SAML application and one VPN endpoint while granting different network access to different groups<\/strong>, following least-privilege principles. <a href=\"https:\/\/docs.aws.amazon.com\/vpn\/latest\/clientvpn-admin\/cvpn-working-rules.html?utm_source=chatgpt.com\">AWS Documentation<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Using memberOf with AWS Client VPN and SAML: A Practical Guide to Group-Based Network Authorization When AWS Client VPN is&#8230; <\/p>\n","protected":false},"author":6,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"series":[],"class_list":["post-3150","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Using memberOf with AWS Client VPN and SAML: A Practical Guide - DevSecOps School<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/devsecopsschool.com\/blog\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Using memberOf with AWS Client VPN and SAML: A Practical Guide - DevSecOps School\" \/>\n<meta property=\"og:description\" content=\"Using memberOf with AWS Client VPN and SAML: A Practical Guide to Group-Based Network Authorization When AWS Client VPN is...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/devsecopsschool.com\/blog\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\/\" \/>\n<meta property=\"og:site_name\" content=\"DevSecOps School\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-29T09:24:44+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-29T09:24:45+00:00\" \/>\n<meta name=\"author\" content=\"rajeshkumar\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"rajeshkumar\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/devsecopsschool.com\\\/blog\\\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/devsecopsschool.com\\\/blog\\\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\\\/\"},\"author\":{\"name\":\"rajeshkumar\",\"@id\":\"https:\\\/\\\/devsecopsschool.com\\\/blog\\\/#\\\/schema\\\/person\\\/3508fdee87214f057c4729b41d0cf88b\"},\"headline\":\"Using memberOf with AWS Client VPN and SAML: A Practical Guide\",\"datePublished\":\"2026-09-29T09:24:44+00:00\",\"dateModified\":\"2026-09-29T09:24:45+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/devsecopsschool.com\\\/blog\\\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\\\/\"},\"wordCount\":1532,\"commentCount\":0,\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/devsecopsschool.com\\\/blog\\\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/devsecopsschool.com\\\/blog\\\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\\\/\",\"url\":\"https:\\\/\\\/devsecopsschool.com\\\/blog\\\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\\\/\",\"name\":\"Using memberOf with AWS Client VPN and SAML: A Practical Guide - DevSecOps School\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/devsecopsschool.com\\\/blog\\\/#website\"},\"datePublished\":\"2026-09-29T09:24:44+00:00\",\"dateModified\":\"2026-09-29T09:24:45+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/devsecopsschool.com\\\/blog\\\/#\\\/schema\\\/person\\\/3508fdee87214f057c4729b41d0cf88b\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/devsecopsschool.com\\\/blog\\\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\\\/#breadcrumb\"},\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/devsecopsschool.com\\\/blog\\\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/devsecopsschool.com\\\/blog\\\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/devsecopsschool.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Using memberOf with AWS Client VPN and SAML: A Practical Guide\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/devsecopsschool.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/devsecopsschool.com\\\/blog\\\/\",\"name\":\"DevSecOps School\",\"description\":\"DevSecOps Redefined\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/devsecopsschool.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/devsecopsschool.com\\\/blog\\\/#\\\/schema\\\/person\\\/3508fdee87214f057c4729b41d0cf88b\",\"name\":\"rajeshkumar\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/787e4927bf816b550f1dea2682554cf787002e61c81a79a6803a804a6dd37d9a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/787e4927bf816b550f1dea2682554cf787002e61c81a79a6803a804a6dd37d9a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/787e4927bf816b550f1dea2682554cf787002e61c81a79a6803a804a6dd37d9a?s=96&d=mm&r=g\",\"caption\":\"rajeshkumar\"},\"url\":\"http:\\\/\\\/devsecopsschool.com\\\/blog\\\/author\\\/rajeshkumar\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Using memberOf with AWS Client VPN and SAML: A Practical Guide - DevSecOps School","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/devsecopsschool.com\/blog\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\/","og_locale":"en_US","og_type":"article","og_title":"Using memberOf with AWS Client VPN and SAML: A Practical Guide - DevSecOps School","og_description":"Using memberOf with AWS Client VPN and SAML: A Practical Guide to Group-Based Network Authorization When AWS Client VPN is...","og_url":"https:\/\/devsecopsschool.com\/blog\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\/","og_site_name":"DevSecOps School","article_published_time":"2026-09-29T09:24:44+00:00","article_modified_time":"2026-09-29T09:24:45+00:00","author":"rajeshkumar","twitter_card":"summary_large_image","twitter_misc":{"Written by":"rajeshkumar","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/devsecopsschool.com\/blog\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\/#article","isPartOf":{"@id":"https:\/\/devsecopsschool.com\/blog\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\/"},"author":{"name":"rajeshkumar","@id":"https:\/\/devsecopsschool.com\/blog\/#\/schema\/person\/3508fdee87214f057c4729b41d0cf88b"},"headline":"Using memberOf with AWS Client VPN and SAML: A Practical Guide","datePublished":"2026-09-29T09:24:44+00:00","dateModified":"2026-09-29T09:24:45+00:00","mainEntityOfPage":{"@id":"https:\/\/devsecopsschool.com\/blog\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\/"},"wordCount":1532,"commentCount":0,"inLanguage":"en","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/devsecopsschool.com\/blog\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/devsecopsschool.com\/blog\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\/","url":"https:\/\/devsecopsschool.com\/blog\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\/","name":"Using memberOf with AWS Client VPN and SAML: A Practical Guide - DevSecOps School","isPartOf":{"@id":"https:\/\/devsecopsschool.com\/blog\/#website"},"datePublished":"2026-09-29T09:24:44+00:00","dateModified":"2026-09-29T09:24:45+00:00","author":{"@id":"https:\/\/devsecopsschool.com\/blog\/#\/schema\/person\/3508fdee87214f057c4729b41d0cf88b"},"breadcrumb":{"@id":"https:\/\/devsecopsschool.com\/blog\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\/#breadcrumb"},"inLanguage":"en","potentialAction":[{"@type":"ReadAction","target":["https:\/\/devsecopsschool.com\/blog\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/devsecopsschool.com\/blog\/using-memberof-with-aws-client-vpn-and-saml-a-practical-guide\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/devsecopsschool.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Using memberOf with AWS Client VPN and SAML: A Practical Guide"}]},{"@type":"WebSite","@id":"https:\/\/devsecopsschool.com\/blog\/#website","url":"https:\/\/devsecopsschool.com\/blog\/","name":"DevSecOps School","description":"DevSecOps Redefined","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/devsecopsschool.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en"},{"@type":"Person","@id":"https:\/\/devsecopsschool.com\/blog\/#\/schema\/person\/3508fdee87214f057c4729b41d0cf88b","name":"rajeshkumar","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/secure.gravatar.com\/avatar\/787e4927bf816b550f1dea2682554cf787002e61c81a79a6803a804a6dd37d9a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/787e4927bf816b550f1dea2682554cf787002e61c81a79a6803a804a6dd37d9a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/787e4927bf816b550f1dea2682554cf787002e61c81a79a6803a804a6dd37d9a?s=96&d=mm&r=g","caption":"rajeshkumar"},"url":"http:\/\/devsecopsschool.com\/blog\/author\/rajeshkumar\/"}]}},"_links":{"self":[{"href":"http:\/\/devsecopsschool.com\/blog\/wp-json\/wp\/v2\/posts\/3150","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/devsecopsschool.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/devsecopsschool.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/devsecopsschool.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/devsecopsschool.com\/blog\/wp-json\/wp\/v2\/comments?post=3150"}],"version-history":[{"count":1,"href":"http:\/\/devsecopsschool.com\/blog\/wp-json\/wp\/v2\/posts\/3150\/revisions"}],"predecessor-version":[{"id":3151,"href":"http:\/\/devsecopsschool.com\/blog\/wp-json\/wp\/v2\/posts\/3150\/revisions\/3151"}],"wp:attachment":[{"href":"http:\/\/devsecopsschool.com\/blog\/wp-json\/wp\/v2\/media?parent=3150"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/devsecopsschool.com\/blog\/wp-json\/wp\/v2\/categories?post=3150"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/devsecopsschool.com\/blog\/wp-json\/wp\/v2\/tags?post=3150"},{"taxonomy":"series","embeddable":true,"href":"http:\/\/devsecopsschool.com\/blog\/wp-json\/wp\/v2\/series?post=3150"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}