The inbound federation Lambda trigger for Amazon Cognito enables programmatic control over federated authentication flows from external identity providers, addressing oversized group attributes in B2B scenarios and automatic account linking for B2C applications. Code examples demonstrate filtering and normalizing SAML group attributes across multiple identity provider formats.