Configure your SSO identity store using the single sign-on guide.
From the Single Sign-On configuration page, customize the start URL for your user portal so that it's easier to remember (Note, your start URL cannot be modified once it has been customized).
Delegate IAM administration from the Management account to the Identity account following the delegated administration guide.
Accept the invitation in your email to join AWS SSO.
Sign out of the IAM management user and sign into the newly created SSO portal.
...
Set Google as an external identity provider using the above guide
Create a dedicated Identity account for managing SSO identities. You can add this to the
accounts.yaml
file from the template.Delegate IAM administration from the Management account to the Identity account following the delegated administration guide.Deploy the sso-sync Lambda to the Identity account. You can follow the guide in the sso sync README.