Amazon Cognito introduces inbound federation Lambda triggers that enable you to transform and customize federated user attributes during the authentication process. You can now modify responses from external SAML and OIDC providers before they are stored in your user pool, providing complete programmatic control over the federation flow without requiring changes to your identity provider configuration..
Inbound federation Lambda trigger addresses current limitations in federated authentication workflows, particularly issues caused by attribute size limits and the need for selective attribute storage from external identity providers. For example, large group attributes from external SAML or OIDC identity providers that exceed Cognito’s 2,048 character limit per attribute can block the authentication flow. This capability allows you to add, override, or suppress attribute values, such as modifying large group attributes, before creating new federated users or updating existing federated user profiles in Cognito.
The new inbound federation Lambda trigger is available through hosted UI (classic) and managed login in all AWS Regions where Amazon Cognito is available. To get started, configure the trigger using the AWS Management Console, AWS Command Line Interface (CLI), AWS Software Development Kits (SDKs), Cloud Development Kit (CDK), or AWS CloudFormation by adding the new parameter to your User Pool LambdaConfig. To learn more, see the Amazon Cognito Developer Guide for implementation examples and best practices.
Categories: general:products/amazon-cognito,marketing:marchitecture/security-identity-and-compliance
Source: Amazon Web Services
Latest Posts
- Dynamics 365 Customer Service – Improve customer outcomes with Service Agent in Microsoft 365 Copilot [MC1331688]
![Dynamics 365 Customer Service - Improve customer outcomes with Service Agent in Microsoft 365 Copilot [MC1331688] 2 pexels stockphotoartist 1070967](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft Dataverse – Enable semantic Dataverse data understanding for agentic use [MC1331636]
![Microsoft Dataverse - Enable semantic Dataverse data understanding for agentic use [MC1331636] 3 pexels eye4dtail 134525](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Notice – Availability of Microsoft (no Teams) Suites in the EEA [MC1330882]
![Notice - Availability of Microsoft (no Teams) Suites in the EEA [MC1330882] 4 pexels alison m 1261203 2399543](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- AWS HealthOmics now supports Nextflow version 26.04


![Dynamics 365 Customer Service - Improve customer outcomes with Service Agent in Microsoft 365 Copilot [MC1331688] 2 pexels stockphotoartist 1070967](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-stockphotoartist-1070967-150x150.webp)
![Microsoft Dataverse - Enable semantic Dataverse data understanding for agentic use [MC1331636] 3 pexels eye4dtail 134525](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-eye4dtail-134525-150x150.webp)
![Notice - Availability of Microsoft (no Teams) Suites in the EEA [MC1330882] 4 pexels alison m 1261203 2399543](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-alison-m-1261203-2399543-150x150.webp)

![(Updated) Microsoft 365: Modern Access Request and Access Denied web page [MC1188599] 7 (Updated) Microsoft 365: Modern Access Request and Access Denied web page [MC1188599]](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-googledeepmind-18068768-96x96.webp)