Our users have a custom Google Workspace attribute (customSchemas.Single_Sign-On.AWS_Username) that holds their AWS username. For external-domain users this differs from their primary email. What is the exact ssosync flag or config parameter to tell ssosync to use this custom attribute for username matching instead of primary email?
We've seen references to --user-match and AWS_SSO_USER_MATCH in the docs but want to confirm the exact syntax for a custom schema attribute.
Our users have a custom Google Workspace attribute (customSchemas.Single_Sign-On.AWS_Username) that holds their AWS username. For external-domain users this differs from their primary email. What is the exact ssosync flag or config parameter to tell ssosync to use this custom attribute for username matching instead of primary email?
We've seen references to --user-match and AWS_SSO_USER_MATCH in the docs but want to confirm the exact syntax for a custom schema attribute.