< ciso
brief />
Tag Banner

All news with #aws iam tag

69 articles

AWS releases advanced Ruby driver wrapper for RDS/Aurora

πŸš€ The AWS Advanced Ruby Driver Wrapper is now generally available for Amazon RDS and Amazon Aurora PostgreSQL and MySQL-compatible databases. It reduces RDS Blue/Green switchover, Aurora Global database switchover and failover times to improve application availability and supports authentication via AWS Secrets Manager and token-based AWS IAM. Built on the community pg and mysql2 drivers, it integrates with Aurora/RDS to detect cluster status and reconnect to promoted writers, and provides aws_postgresql and aws_mysql2 ActiveRecord adapters so applications require no code changes.
read more β†’

AWS STS VPC endpoints for OIDC discovery

πŸ”’ AWS IAM outbound identity federation now supports VPC endpoints for OIDC discovery, allowing workloads to access OIDC metadata and JWKS verification keys over AWS PrivateLink without traversing the public internet. This enables short-lived JWTs from AWS STS to be verified by external services while keeping traffic inside the AWS network. The feature addresses network security requirements for VPCs with restricted internet access and is available in all commercial, GovCloud (US), and China Regions with standard PrivateLink pricing.
read more β†’

AWS August 2026 Security Update Digest

πŸ”’ August’s AWS Security digest highlights new service capabilities, compliance updates, and hands-on resources across identity, data protection, AI security, detection, and governance. It summarizes 20+ blog posts, security bulletins, and 17 code samples focused on agent governance, credential protection, and automated compliance. The update emphasizes prompt patching and practical deployment guidance for enterprise security teams.
read more β†’

Detecting and Quarantining Exposed AWS IAM Keys

πŸ”Ž This article examines how AWS mitigates publicly exposed IAM access keys through the AWSCompromisedKeyQuarantine managed policy, tracing its evolution across versions and explaining its role in responding to leaked credentials. It details the GitHub secret scanning partnership with AWS, a real-world timeline from a public exposure test, and practical monitoring strategies security teams can use to detect quarantine events in their logging environments. The piece also outlines Palo Alto Networks services that can assist organizations in assessment and incident response.
read more β†’

AWS HealthOmics adds IAM session policy support

πŸ” AWS HealthOmics now supports IAM session policies, allowing you to restrict permissions for individual runs without creating and managing multiple IAM roles. An IAM session policy is an inline policy that limits the maximum permissions of a run by intersecting with the underlying identity-based policy. This enables per-run scopingβ€”such as restricting access to a tenant's S3 buckets or specific S3 objectsβ€”without provisioning separate roles. Support is available in all Regions where HealthOmics is offered.
read more β†’

Amazon Redshift adds IAM Identity Center via EVR

πŸ”’ Amazon Redshift now supports AWS IAM Identity Center authentication for provisioned clusters and serverless workgroups configured with enhanced VPC routing (EVR). This enables single sign-on using corporate credentials while keeping traffic inside your Amazon VPC and on the AWS network, meeting data residency and network-isolation requirements. Redshift validates and exchanges IAM Identity Center tokens over AWS PrivateLink interface VPC endpoints inside the VPC and supports multi-Region Identity Center replication.
read more β†’

Automate IAM Identity Center governance and reporting

πŸ” This post explains how to plan and automate governance for AWS IAM Identity Center across an AWS Organization. It outlines integration with external IdPs, recommended delegation and IAM permissions, and naming conventions to improve discoverability. The article describes a sample solution that uses AWS CDK to deploy reporting and remediation stacks to discover Identity Center applications, generate CSV reports, and optionally enforce assignment policies. It emphasizes cross-team planning, detective controls, and testing before remediation.
read more β†’

IAM Roles Anywhere Java SDK v2 plugin available

πŸ› οΈ The AWS Identity and Access Management (IAM) Roles Anywhere plugin for the AWS SDK for Java v2 lets applications running outside AWS obtain temporary credentials directly inside the Java process. The JVM-hosted plugin removes the need for a separate credential helper or credential_process configuration and integrates with client builders to auto-resolve and refresh credentials. It supports RSA, EC, and ML-DSA keys, requires Java 8+, and is available across all AWS Regions at no extra charge.
read more β†’

AWS Lambda adds full IAM resource-based policy support

πŸ”’ AWS Lambda functions now support full Identity and Access Management (IAM) resource-based policies, enabling platform and security teams to define granular permissions for multiple principals and actions within a single policy. This replaces the previous per-principal permission model and permits the use of the full range of IAM condition keys, such as source IP or principal tag restrictions. Policies can be managed via the Lambda console JSON editor, AWS CLI, SDKs, CloudFormation, and SAM. The feature is available in all AWS commercial Regions at no extra cost.
read more β†’

AWS Partner Central Adds OAuth for MCP Access

πŸ” Partners can now authorize AWS Partner Central agents from third-party tools like Amazon Quick and Kiro using AWS Sign-In and OAuth, eliminating the need for separate SigV4 proxies or console sign-ins. This change lets partners use their existing AWS identities, IAM permissions, and governance controls to grant agent access without extra authentication software. Administrators retain control via IAM policies, token introspection and revocation, dynamic client registration, and CloudTrail auditing. OAuth support is available through the Partner Central agents MCP Server in US East (N. Virginia).
read more β†’

AWS IAM increases default managed policies per role

πŸ”’ AWS Identity and Access Management (IAM) has increased the default quota for managed policies attached to a role from 10 to 20. This change reduces the need to request Service Quotas when adopting best practices such as separating permissions into purpose-specific policies or when onboarding AWS Partner products that attach additional managed policies. If more than 20 managed policies are needed, customers can request a quota increase up to 25 via Service Quotas. The update is applied automatically across all commercial AWS Regions, AWS GovCloud (US), and China Regions with no customer action required.
read more β†’

AWS IAM Adds Outbound Federation in EU Sovereign Cloud

πŸ” AWS Identity and Access Management (IAM) now supports outbound identity federation in the AWS European Sovereign Cloud (Germany), enabling workloads to obtain short-lived JSON Web Tokens (JWTs) to authenticate with external services. This feature allows secure access to third-party clouds, SaaS, and self-hosted applications without long-term credentials. Administrators can enforce token properties and control generation via IAM policies and audit usage with CloudTrail to meet sovereignty and compliance needs.
read more β†’

AWS updates sign-in and session selection experience

πŸ”’ Amazon Web Services is rolling out a redesigned AWS Sign-In and session selection experience to a subset of customers, introducing a unified email entry point and refreshed session management. Existing sign-in methods and credentials continue to work, and sign-in with supported identity providers is available only for accounts created with those providers. Organizations using IAM Identity Center or federation should continue to use their existing portals, and administrators who rely on browser automation should review the changes for compatibility.
read more β†’

AWS IAM Role Manager simplifies role provisioning

πŸ”’ IAM Role Manager automates the creation and attachment of IAM roles as you build resources in supported AWS service consoles. When enabled, AWS provisions roles from managed templates or reuses suitable ones, letting you start services quickly while maintaining full visibility and control. Roles are ordinary IAM roles you can review, edit, or delete, and IAM Access Analyzer can later recommend least-privilege policies.
read more β†’

AWS IAM Role Manager Now Generally Available

πŸ›‘οΈ Today AWS announces the general availability of Role Manager, a capability in AWS Identity and Access Management (IAM) that automatically creates or reuses IAM roles required by supported AWS service consoles. Role Manager can be enabled or disabled at any time and exposes the AWS-managed templates it deploys. At launch it supports six service consoles, including AWS Lambda and Amazon EventBridge, and is available in all Regions except AWS GovCloud (US) and China Regions.
read more β†’

One-click multi-Region option for IAM Identity Center

πŸ”’ AWS IAM Identity Center now offers a one-click multi-Region option when creating a new organization instance, simplifying what previously required multiple manual steps. The multi-Region instance choice automatically creates a customer managed multi-Region KMS key and replicates the instance to an additional Region to provide resilient access. Customers can also choose single-Region or custom instances, with custom allowing use of existing customer managed KMS keys and fine-grained Region configuration.
read more β†’

IAM Policy Simulator integrated into IAM console

πŸ› οΈ AWS has updated the IAM Policy Simulator with three key changes: it is now integrated into the IAM console, it supports testing of service control policies (SCPs), and it offers greater modeling flexibility for realistic scenarios. The simulator replaces the standalone site and lets you include SCPs to evaluate interactions with identity and resource policies. New options allow excluding specific policies to model removal scenarios, and cross-account simulations report per-policy decisions with matched statements shown for denials. These enhancements aid automation of policy unit tests, detection of over-permissive access, and validation of guardrails across regions where the simulator is available.
read more β†’

Amazon GameLift Streams adds IAM role support

πŸ” Amazon GameLift Streams now allows assigning an IAM role to a stream session so streamed applications can securely access AWS resources like Amazon S3 and DynamoDB. By passing a RoleArn when starting a session, applications receive short-lived, auto-refreshing credentials via the standard AWS SDK credential chain with no code changes. The service validates role configuration at session start and the console offers a pre-filled trust policy template for easy setup; the feature is available in all Regions where GameLift Streams runs.
read more β†’

AWS IAM Identity Center Gains FedRAMP Class C

πŸ”’ AWS IAM Identity Center has achieved FedRAMP Class C authorization and is now in scope for the US East (Ohio), US East (N. Virginia), US West (N. California), and US West (Oregon) Regions. This allows organizations to use the service to enable workforce access to AWS accounts and applications that require FedRAMP Class C compliance. The announcement reiterates that the Federal Risk and Authorization Management Program (FedRAMP) standardizes security assessment and continuous monitoring for cloud services and that IAM Identity Center is the recommended AWS service for managing workforce access. Additional compliance and product guidance is available in the AWS documentation and user guides.
read more β†’

Amazon RDS IAM Database Authentication Scales Dynamically

πŸ”’ Amazon RDS now supports dynamic connection rate scaling for IAM database authentication, so authentication throughput scales with instance resources. This allows enterprise workloads to use IAM authentication for high-volume connection patterns while depending on available CPU and memory. AWS recommends reusing IAM principals or authentication tokens to optimize performance. The feature is available in all Regions, including AWS GovCloud (US), for Aurora, PostgreSQL, MySQL, and MariaDB.
read more β†’