Connecting Sources
You can configure the AWS SaaS and Microsoft Entra SaaS connectors as sources to discover and aggregate agents and other non-human identities.
Configuring the AWS SaaS Connector
To configure the AWS SaaS connector to discover non-human identities, you'll create a CloudFormation StackSet to create an IAM role. This will allow Agentic Fabric to discover Amazon Bedrock agents and other non-human identities.
Important
If your organization already has configured an AWS SaaS source, you can use the existing source for agent discovery. The fields will be prepopulated with the source's information. You can edit these fields to configure a new integration.
To configure the AWS SaaS connector:
-
In the AWS Bedrock & AgentCore section, enter a name for the source in the Source Name field.
-
In the Source Owner field, select the identity who will own the source.
-
In the StackSet Name field, enter a name for the StackSet.
-
In the Administrator Account ID field, enter your Administrator Account ID.
-
In the Role Name field, enter the IAM role name that will be created on your AWS accounts.
-
In the Region field, enter the region name for the AWS data center. The default region is us-east-1.
-
Select Create StackSet.
Important
To deploy the IAM role across your accounts, an administrator must approve the delegation request in the AWS console. After access has been approved, StackSet events will start to populate on the Connect Sources page.
-
Select Next to configure the Microsoft Entra SaaS Connector or select Continue to connect your EDR or SIEM tool.
Configuring the Microsoft Entra SaaS Connector
If your organization has already configured a Microsoft Entra source, you can use the existing source for agent discovery. The fields will be prepopulated with the source's information. You can edit these fields to configure a new integration.
-
In the Microsoft Entra section, enter a unique name for the source in the Source Name field.
-
In Source Owner field, select the identity who will own the source.
-
In the Description field, enter a unique description for the source to distinguish it from similar connections.
-
In the Set up our Authentication section, enter the Microsoft Entra API details for OAuth2 in the Client ID and Client Secret fields.
-
In Domain Name field, enter the name of the Microsoft Entra domain to be managed.
-
Select Continue to save these changes and continue setting up Agentic Fabric.
Documentation Feedback
Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.