SageMaker Unified Studio supports IAM permissions boundaries
π Amazon SageMaker Unified Studio now supports custom IAM permissions boundaries so organizations enforcing Service Control Policies (SCPs) can provision projects without changing their security posture. When creating a project, SageMaker provisions three IAM roles β a project user role, an Amazon Bedrock service role, and a Bedrock Lambda execution role β and administrators can specify a permissions boundary in the Tooling blueprint configuration. The boundary is attached to all three roles at creation, satisfying SCP requirements and limiting role capabilities while allowing automatic project provisioning across all supported AWS Regions.
