< ciso
brief />
Tag Banner

All news with #iam tag

228 articles

CloudWatch Centralization Adds Tag Propagation

🔔 Amazon CloudWatch Centralization now copies log group tags from source accounts to destination log groups created by centralization rules. Tag propagation preserves cost, ownership, and compliance tags so teams can scope access and report spend centrally. The feature syncs tags based on propagation behavior chosen in the centralization rule and is available in all Regions where CloudWatch Centralization is offered.
read more →

Amazon DynamoDB Streams Adds ABAC Support

🔒 Amazon DynamoDB Streams now supports attribute-based access control (ABAC), allowing tag-based conditions in IAM policies to control stream access. You can attach up to 50 tags per stream and use them to permit or deny actions, enabling environment and team segregation without proliferating IAM policies. Stream tags are independent from table tags, available in all commercial AWS Regions and AWS GovCloud (US), and there is no additional cost to use this feature.
read more →

SageMaker notebooks add trusted identity propagation

🧭 Amazon SageMaker Notebooks now support Trusted Identity Propagation (TIP) with Amazon Athena, Amazon Redshift, and Amazon EMR Serverless, enabling per-user access control for data analytics. When connected to a TIP-enabled compute in a TIP-enabled Project, each notebook user's IAM Identity Center identity flows through to AWS Lake Formation, ensuring they see only the tables, columns, and rows their permissions allow. TIP provides per-user data boundaries, full audit attribution with CloudTrail, and reduces admin friction by automatically propagating identity through existing compute connections without extra logins or role management. The feature is available in all Regions where Amazon SageMaker Unified Studio is available.
read more →

Propagate user authorization in AI agents with Bedrock

🛡️ This post demonstrates patterns for propagating user authorization context when building AI agents with Amazon Bedrock AgentCore, ensuring each user only sees data they’re allowed to access. It explains how to embed department or custom claims in tokens via Amazon Cognito pre token generation triggers and how the AgentCore Runtime inbound JWT authorizer validates those claims before invoking agent code. The guidance shows moving enforcement into infrastructure—using STS session tags, per-request AssumeRoleWithWebIdentity for DynamoDB, metadata filters for Bedrock Knowledge Bases, and on‑behalf‑of token exchange for external SaaS—to reduce risk from compromised agents.
read more →

IAM Policy Autopilot adds Terraform plan support

🔧 IAM Policy Autopilot now accepts Terraform plan files to generate baseline IAM policies. The open source tool, launched at re:Invent 2025, deterministically analyzes a plan to produce scoped policies that reference specific resource ARNs where possible. This capability complements existing Terraform-aware analysis and addresses the most requested feature since launch. IAM Policy Autopilot runs locally at no additional cost.
read more →

UT San Antonio IT Systems Taken Offline After Incident

🔒 The University of Texas San Antonio took several IT systems offline after detecting attempted unauthorized activity at the network edge, prompting containment measures by University Technology Solutions and partners. Officials say there is no evidence of data access or exfiltration so far, though the outage disrupted online registration, tuition payments and phone systems ahead of term start. Students were granted extensions and instructed to reset passphrases as remediation steps continue.
read more →

Practical IAM Compliance: Requirements and Best Practices

🔐 This guide defines IAM compliance as proving that identity and access controls are not only documented but enforced across users, applications, infrastructure, and non-human identities. It explains key obligations from frameworks like SOX, PCI DSS, HIPAA, ISO/IEC 27001, NIST SP 800-53, and GDPR, and highlights evidence gaps between policy intent and runtime execution. The article outlines core controls—least privilege, segregation of duties, MFA, lifecycle management—and urges continuous, application-layer verification rather than periodic reviews.
read more →

AWS IAM Role Manager simplifies role provisioning

🔒 IAM Role Manager automates the creation and attachment of IAM roles as you build resources in supported AWS service consoles. When enabled, AWS provisions roles from managed templates or reuses suitable ones, letting you start services quickly while maintaining full visibility and control. Roles are ordinary IAM roles you can review, edit, or delete, and IAM Access Analyzer can later recommend least-privilege policies.
read more →

Amazon Bedrock adds IAM principal cost allocation

🔒 Amazon Bedrock now supports cost allocation by AWS Identity and Access Management (IAM) principal — including IAM users and roles — for model inference requests made through the bedrock-mantle endpoint. This extends existing support for the bedrock-runtime endpoint and enables customers to attribute inference costs to teams, projects, or applications using IAM principal tags. Activate IAM principal tags in the AWS Billing and Cost Management console to analyze costs in AWS Cost Explorer or include caller identity data in AWS Cost and Usage Report 2.0.
read more →

AWS IAM launches Account Access Manager feature

🔐 AWS Identity and Access Management (IAM) introduced Account Access Manager, simplifying assignment of IAM roles to workforce users and groups from AWS IAM Identity Center. Administrators can now manage role assignments centrally while retaining per-account role flexibility, using the AWS IAM console, SDKs, CloudFormation, and CDK. The feature consolidates permissions management, user awareness, and a single federation point at no additional cost.
read more →

A decade of AWS Managed Microsoft AD evolution

🔒 Over ten years, AWS Managed Microsoft AD evolved from a basic managed Microsoft Active Directory offering into a foundational enterprise identity service integrated across more than 20 AWS services. The service reduced operational overhead by handling domain controllers, HA, backups, patching, and replication while adding features like schema extensions, gMSA, multi-Region replication, and CRUD APIs. Recent additions include Hybrid Edition, self-service edition upgrades, and integrations for database, file, and remote-access authentication.
read more →

Amazon Cognito added to Agent Toolkit skills

🔧 The Amazon Cognito (aws-auth) skill is now included in the Agent Toolkit for AWS, enabling AI coding agents to set up, configure, secure, and troubleshoot Amazon Cognito using best-practice workflows. The skill supports user pools, app clients, OAuth 2.0 flows, token and JWT authorizer management, passkey/WebAuthn enrollment, threat protection, Lambda triggers, and identity pools. When used with the AWS MCP Server, commands run with IAM guardrails and CloudTrail audit logging; it also works standalone via the AWS CLI.
read more →

Securing Amazon S3: Identify and Remediate Over‑Permissions

🔒 This post explains how to detect and remediate over‑permissioned Amazon S3 buckets across single‑ or multi‑account AWS environments. It outlines a five‑phase workflow—setup, detection, remediation, continuous monitoring, and cleanup—while recommending AWS Config, Security Hub, EventBridge, IAM Access Analyzer, and Lambda‑based scanning scripts. The guidance focuses on methodology and customization for security engineers, cloud architects, and DevOps teams.
read more →

OpenSearch UI adds network access controls

🔒 Amazon OpenSearch Service now supports network access controls for OpenSearch UI applications, enabling administrators to restrict access to approved networks using IAM condition keys like aws:SourceVpce, aws:SourceVpc, and aws:SourceIp. You can enforce restrictions via identity-based policies, VPC endpoint policies, and organization-wide resource control policies (RCPs), which can block off-network users before authentication. This feature is available in all Regions where OpenSearch UI is offered.
read more →

Amazon Cognito adds self-service provisioned limits

🔒 Today Amazon Cognito launches provisioned limits in the console to let teams self-service authentication rate adjustments in minutes. The feature separates an account-level maximum (managed via Service Quotas) from a provisioned limit you pay for and control in the Amazon Cognito console, enabling rapid scaling for events like Black Friday. It supports granular RPS adjustments, programmatic APIs, and cost optimization by billing only for provisioned capacity above defaults.
read more →

AWS Identity Center makes account management optional

🔒 AWS IAM Identity Center now lets administrators choose whether to enable AWS account access management when creating a new instance. This option permits using Identity Center solely for managing access to AWS applications, without provisioning access to AWS accounts. The setting is available during initial configuration, does not affect existing instances, and can be changed later via instance settings or the UpdateInstance API. The capability is available in all Regions where IAM Identity Center is offered.
read more →

AWS Organizations adds account quota visibility in ServiceQuotas

🔍 AWS Organizations customers can now view their maximum account quota and current utilization directly in AWS Service Quotas. This eliminates the need to contact AWS Support or account teams to determine account limits. Administrators can check quotas from the management account via the Service Quotas console or the GetServiceQuota API. The feature is available now in US East (N. Virginia).
read more →

AI Elevates Need for Cybersecurity Fundamentals

🔒 AI-driven tools are exposing long-standing security gaps while accelerating familiar attack techniques. Experts stress that core practices—identity management, patching, configuration hygiene, multifactor authentication, and zero-trust—remain essential and must be applied consistently. AI increases speed, scale, and customization of attacks, but does not eliminate the need for human oversight, judgment, and accountability.
read more →

IAM Policy Simulator integrated into IAM console

🛠️ AWS has updated the IAM Policy Simulator with three key changes: it is now integrated into the IAM console, it supports testing of service control policies (SCPs), and it offers greater modeling flexibility for realistic scenarios. The simulator replaces the standalone site and lets you include SCPs to evaluate interactions with identity and resource policies. New options allow excluding specific policies to model removal scenarios, and cross-account simulations report per-policy decisions with matched statements shown for denials. These enhancements aid automation of policy unit tests, detection of over-permissive access, and validation of guardrails across regions where the simulator is available.
read more →

AlloyDB adds IAM group authentication for enterprises

🔒 Google Cloud announced preview support for Identity and Access Management (IAM) group authentication in AlloyDB, extending an identity-driven, passwordless access model to enterprise database workloads. The feature aligns AlloyDB with Cloud SQL by enabling group-based access controls to reduce individual account sprawl, simplify on- and off-boarding, and improve auditing. It also helps secure AI agents by ensuring actions map to user identities and limiting privilege escalation.
read more →