<div dir="ltr">One of the members of our cloud services team is in groups that grants 270+ roles in AWS.<div>He has access if he is in <= 272 groups.  </div><div><br></div><div>Once he hits 273, when he tries to access the AWS web console, AWS throws up an error message stating that the SAML response from our IDP is invalid.  He can, however, continue to obtain credentials using <a href="https://pypi.org/project/awscli-login/">awscli-login</a>.</div><div><br></div><div>Our IDP isn't throwing any errors.  The SAML response we're sending to them looks fine to me.</div><div><br></div><div>He said he's spoken to an architect at AWS who says there is no limit to the number of roles we can assert.</div><div><br></div><div>Anyone run into this before?</div><div>Liam</div></div>