< ciso
brief />
Tag Banner

All news with #aws iam tag

60 articles

AWS Partner Central Adds OAuth for MCP Access

๐Ÿ” Partners can now authorize AWS Partner Central agents from third-party tools like Amazon Quick and Kiro using AWS Sign-In and OAuth, eliminating the need for separate SigV4 proxies or console sign-ins. This change lets partners use their existing AWS identities, IAM permissions, and governance controls to grant agent access without extra authentication software. Administrators retain control via IAM policies, token introspection and revocation, dynamic client registration, and CloudTrail auditing. OAuth support is available through the Partner Central agents MCP Server in US East (N. Virginia).
read more โ†’

AWS IAM increases default managed policies per role

๐Ÿ”’ AWS Identity and Access Management (IAM) has increased the default quota for managed policies attached to a role from 10 to 20. This change reduces the need to request Service Quotas when adopting best practices such as separating permissions into purpose-specific policies or when onboarding AWS Partner products that attach additional managed policies. If more than 20 managed policies are needed, customers can request a quota increase up to 25 via Service Quotas. The update is applied automatically across all commercial AWS Regions, AWS GovCloud (US), and China Regions with no customer action required.
read more โ†’

AWS IAM Adds Outbound Federation in EU Sovereign Cloud

๐Ÿ” AWS Identity and Access Management (IAM) now supports outbound identity federation in the AWS European Sovereign Cloud (Germany), enabling workloads to obtain short-lived JSON Web Tokens (JWTs) to authenticate with external services. This feature allows secure access to third-party clouds, SaaS, and self-hosted applications without long-term credentials. Administrators can enforce token properties and control generation via IAM policies and audit usage with CloudTrail to meet sovereignty and compliance needs.
read more โ†’

AWS updates sign-in and session selection experience

๐Ÿ”’ Amazon Web Services is rolling out a redesigned AWS Sign-In and session selection experience to a subset of customers, introducing a unified email entry point and refreshed session management. Existing sign-in methods and credentials continue to work, and sign-in with supported identity providers is available only for accounts created with those providers. Organizations using IAM Identity Center or federation should continue to use their existing portals, and administrators who rely on browser automation should review the changes for compatibility.
read more โ†’

AWS IAM Role Manager simplifies role provisioning

๐Ÿ”’ IAM Role Manager automates the creation and attachment of IAM roles as you build resources in supported AWS service consoles. When enabled, AWS provisions roles from managed templates or reuses suitable ones, letting you start services quickly while maintaining full visibility and control. Roles are ordinary IAM roles you can review, edit, or delete, and IAM Access Analyzer can later recommend least-privilege policies.
read more โ†’

AWS IAM Role Manager Now Generally Available

๐Ÿ›ก๏ธ Today AWS announces the general availability of Role Manager, a capability in AWS Identity and Access Management (IAM) that automatically creates or reuses IAM roles required by supported AWS service consoles. Role Manager can be enabled or disabled at any time and exposes the AWS-managed templates it deploys. At launch it supports six service consoles, including AWS Lambda and Amazon EventBridge, and is available in all Regions except AWS GovCloud (US) and China Regions.
read more โ†’

One-click multi-Region option for IAM Identity Center

๐Ÿ”’ AWS IAM Identity Center now offers a one-click multi-Region option when creating a new organization instance, simplifying what previously required multiple manual steps. The multi-Region instance choice automatically creates a customer managed multi-Region KMS key and replicates the instance to an additional Region to provide resilient access. Customers can also choose single-Region or custom instances, with custom allowing use of existing customer managed KMS keys and fine-grained Region configuration.
read more โ†’

IAM Policy Simulator integrated into IAM console

๐Ÿ› ๏ธ AWS has updated the IAM Policy Simulator with three key changes: it is now integrated into the IAM console, it supports testing of service control policies (SCPs), and it offers greater modeling flexibility for realistic scenarios. The simulator replaces the standalone site and lets you include SCPs to evaluate interactions with identity and resource policies. New options allow excluding specific policies to model removal scenarios, and cross-account simulations report per-policy decisions with matched statements shown for denials. These enhancements aid automation of policy unit tests, detection of over-permissive access, and validation of guardrails across regions where the simulator is available.
read more โ†’

Amazon GameLift Streams adds IAM role support

๐Ÿ” Amazon GameLift Streams now allows assigning an IAM role to a stream session so streamed applications can securely access AWS resources like Amazon S3 and DynamoDB. By passing a RoleArn when starting a session, applications receive short-lived, auto-refreshing credentials via the standard AWS SDK credential chain with no code changes. The service validates role configuration at session start and the console offers a pre-filled trust policy template for easy setup; the feature is available in all Regions where GameLift Streams runs.
read more โ†’

AWS IAM Identity Center Gains FedRAMP Class C

๐Ÿ”’ AWS IAM Identity Center has achieved FedRAMP Class C authorization and is now in scope for the US East (Ohio), US East (N. Virginia), US West (N. California), and US West (Oregon) Regions. This allows organizations to use the service to enable workforce access to AWS accounts and applications that require FedRAMP Class C compliance. The announcement reiterates that the Federal Risk and Authorization Management Program (FedRAMP) standardizes security assessment and continuous monitoring for cloud services and that IAM Identity Center is the recommended AWS service for managing workforce access. Additional compliance and product guidance is available in the AWS documentation and user guides.
read more โ†’

Amazon RDS IAM Database Authentication Scales Dynamically

๐Ÿ”’ Amazon RDS now supports dynamic connection rate scaling for IAM database authentication, so authentication throughput scales with instance resources. This allows enterprise workloads to use IAM authentication for high-volume connection patterns while depending on available CPU and memory. AWS recommends reusing IAM principals or authentication tokens to optimize performance. The feature is available in all Regions, including AWS GovCloud (US), for Aurora, PostgreSQL, MySQL, and MariaDB.
read more โ†’

IAM Identity Center: Customer Managed App Account Access

๐Ÿ” IAM Identity Center now lets customer managed applications programmatically discover user-assigned AWS accounts and roles and retrieve temporary credentials for account access. If your application authenticates users via an external identity provider (IdP), you can configure that IdP as a trusted token issuer and enable AWS account access so users who already signed in through the IdP can obtain credentials without re-authenticating. Administrators must explicitly enable this for each customer managed application, and only management account or delegated administrators can grant the capability, ensuring centralized governance. The feature is available across all commercial, GovCloud (US), and China Regions.
read more โ†’

Shai Hulud CI/CD to Redshift breach analysis

๐Ÿ” This FortiGuard Labs analysis examines the Shai Hulud supply chain worm that poisoned CI/CD dependencies to harvest Jenkins credentials and pivot into AWS. The report outlines a midโ€‘May 2026 incident where FortiCNAPP traced external use of a Jenkins instance role, IAM escalation to a cloudops-monitor identity, and subsequent Redshift data extraction. It highlights detection signals, MITRE mappings, and recommended containment actions.
read more โ†’

Restrict AWS Console Access Using Sign-In Policies

๐Ÿ”’ This post explains how AWS Sign-In now supports resource-based policies and resource control policies (RCPs) to restrict AWS Management Console and AWS CLI sign-in to expected networks such as corporate IP ranges, on-premises data center networks, and Amazon VPCs. It walks through a financial services use case that enforces console sign-in from a corporate network, shows how to create and enable a sign-in resource permission statement, and describes verification via AWS CloudTrail. The article also contrasts single-account resource-based policies with organization-wide RCPs and explains integration with AWS Management Console Private Access and the broader data perimeter framework.
read more โ†’

IAM Identity Center adds separate account and app quotas

๐Ÿ”” AWS IAM Identity Center now supports separate quotas for AWS accounts and applications. By default, administrators can configure up to 7,000 AWS accounts and 7,000 applications independently, so use of one does not reduce capacity for the other. Existing customers with higher limits retain those limits automatically. Quota increases remain available via the AWS Service Quotas console.
read more โ†’

Accelerating AWS security investigations with Kiro CLI

๐Ÿ” This post shows how Kiro CLI, an AI-powered command line assistant, speeds AWS security investigations by proposing, explaining, and optionally executing AWS CLI commands while documenting each step. It demonstrates a GuardDuty-driven investigation following the AWS Security Incident Response Guide: triage, EC2 and IAM assessment, CloudTrail analysis, containment, and remediation. The walkthrough highlights benefits like faster triage, automated CloudTrail queries, and guided remediation, while advising human validation and forensic preservation.
read more โ†’

AWS Management Console Private Access Launch

๐Ÿ”’ AWS Management Console Private Access now lets customers reach the AWS Console from VPCs without any internet connectivity, enabling management of AWS infrastructure in air-gapped and strictly controlled networks. The feature routes console traffic through VPC endpoints using AWS PrivateLink, letting customers enforce VPC endpoint policies and existing IAM, Service Control, and Resource Control policies. Available in all AWS commercial regions, customers pay only for the underlying VPC endpoint usage and data processing.
read more โ†’

Amazon S3 Access Grants Arrive in Germany Region

๐Ÿ›ˆ Amazon S3 Access Grants are now available in the AWS European Sovereign Cloud (Germany) Region. The feature maps identities from directories like Microsoft Entra ID and AWS IAM principals to S3 datasets, enabling automated, scalable data permission management. This simplifies granting S3 access to end users based on corporate identities. Check the AWS Region Table for full regional availability and refer to the product page for details.
read more โ†’

Simplified S3 Tables and Iceberg permissions in GovCloud

๐Ÿ”’ AWS Glue Data Catalog now supports IAM-based authorization for Amazon S3 Tables and Apache Iceberg materialized views in AWS GovCloud (US) Regions. This change lets you consolidate required permissions for storage, catalog, and query engines into a single IAM policy. The capability eases integration with analytics services such as Amazon Athena, Amazon EMR, Amazon Redshift, and AWS Glue. You can still opt in to AWS Lake Formation for fine-grained access controls.
read more โ†’

AWS VPC IPAM adds tagging for allocations

๐Ÿ›ˆ Amazon VPC IP Address Manager (IPAM) now supports tags on IPAM pool allocations, letting customers organize, govern, and control access to individual IP address allocations using existing tagging workflows. Tags can be applied at creation or added to existing allocations and referenced in AWS Identity and Access Management and Service Control Policies for centralized governance. Administrators can enforce environment-based allocation controls and teams can search and filter allocations by tag across accounts. The feature is available in all AWS Regions where IPAM is supported at no additional cost.
read more โ†’