and department can be used, and how custom attributes like SSMSessionRunAs can be used to pass these attributes into Amazon Web Services (AWS) from an external identity provider (IdP) using SAML 2.0 assertion. AWS SSO added support for ABAC to enable you to create fine-grained permissions for your workforce in AWS using user attributes.
Read full article on AWS Security Blog