< ciso
brief />
Tag Banner

All news with #iam tag

228 articles · page 3 of 12

Amazon Connect allows seven security profiles per user

🔒 Amazon Connect Customer now permits assigning up to seven security profiles per user, up from two, enabling granular, scoped permissions for agents who support multiple lines of business. This supports tag-based or hierarchy-based access controls so each profile can grant access only to resources for a specific division. The change improves flexibility to implement least-privilege access aligned with organizational structure and is available in all AWS regions where Amazon Connect is offered.
read more →

Guardian Agents: The Next Layer of Identity

🛡️ This guide examines how agentic AI shifted enterprise identity risks and why existing IAM controls fall short. It explains how AI agents inherit human permissions, traverse systems at machine speed, and create an expanding population of autonomous identities often deployed without security review. The piece outlines the guardian agent concept: a purpose-built runtime control layer that inventories agents, baselines behavior, detects anomalies, and enforces least-privilege at execution time to close the governance gap.
read more →

AWS Sign-in adds resource and control policies

🔐 AWS Sign-in now supports resource-based policies and resource control policies (RCPs) for the AWS Management Console. These policies let administrators restrict console sign-in to expected networks and are evaluated during sign-in and when the console session requests new credentials. Resource-based policies target individual AWS accounts while RCPs apply organization-wide via AWS Organizations. Administrators can combine these controls with AWS Management Console Private Access to manage allowed sign-in networks and account access across their environment.
read more →

Governing the growing ghost workforce risk

🛡️ Enterprises are facing an invisible workforce: non-human identities (bots, service accounts, API keys, tokens, certificates) that now often outnumber humans. These ghost identities authenticate constantly across environments and, when unmanaged, accumulate privileges and risks. The industry has seen incidents where forgotten or third-party machine identities enabled widespread breaches, and a looming 2026 certificate-expiration wave threatens cascading outages. Organisations must prioritise governance—discovering NHIs, assigning ownership, auditing privileges, and addressing imminent certificate expirations—before tool selection.
read more →

Fine-grained B2C Access Control with Cognito

🔐 This article demonstrates how to implement enterprise-grade authentication and authorization for a Streamlit sample application using Amazon Cognito for identity and Amazon Verified Permissions with Cedar policies for fine-grained access control. It outlines a layered architecture that separates identity verification, authorization evaluation, application logic, and enforcement to reduce blast radius. The post explains Cedar policy anatomy and common patterns—ownership, role-based, hierarchical, and emergency access—plus evaluation precedence where forbid policies take priority. Practical guidance covers required tools, provisioning steps, policy design tips, and testing recommendations to help developers scale secure applications.
read more →

AWS MCP Server Adds Cross-Account Cross-Role Access

🚀 Today AWS introduced cross-account and cross-role access for the AWS Model Context Protocol (MCP) Server, part of the Agent Toolkit for AWS. This update lets AI coding agents such as Kiro, Claude Code, or Codex operate across multiple AWS accounts and IAM roles within a single session without restarts. Previously, changing accounts required stopping the session, updating local credentials, and restarting the MCP server; now agents can specify a profile per command. The feature is intended to streamline multi-account workflows and reduce context-switch friction. The MCP Server is available in US East (N. Virginia) and Europe (Frankfurt).
read more →

Amazon Cognito adds multi-Region replication support

🔁 Amazon Cognito now supports multi-Region replication, allowing near real-time synchronization of user and machine identity data — including credentials, user pool configurations, and federation setups — to a standby user pool in a designated secondary Region. This feature improves authentication resilience by providing a replica that can accept traffic during regional disruptions, preserving signed-in sessions and enabling users to authenticate with existing credentials. Multi-Region replication is offered as an add-on for user pools in the Essentials or Plus tiers and is available across multiple AWS Regions. Administrators can configure replication through the AWS Console, CLI, or SDKs; pricing and implementation guidance are provided in AWS documentation.
read more →

Customize Federated Sign‑In with Cognito Lambda Trigger

🔐 This post introduces the new inbound federation Lambda trigger for Amazon Cognito, which intercepts external IdP responses so you can transform, filter, and enrich attributes before a user profile is created. It explains how the trigger receives SAML and OIDC attributes, and outlines common B2B and B2C problems such as oversized group lists and duplicate accounts from different social sign-ins. The article shows how to normalize group attributes, filter excessive data, and implement automated account linking to maintain a single primary identity. It also covers performance and error-handling best practices for Lambda functions.
read more →

SageMaker Studio quick setup with model customization

🔧 Amazon SageMaker Studio's quick setup now completes in under twenty seconds, down from over two minutes, letting users rapidly move from sign-in to a fully configured Studio environment. Newly created Studio environments automatically receive serverless model customization permissions via a new managed policy, AmazonSageMakerModelCustomizationCoreAccess, enabling fine-tuning, evaluation, and deployment without manual IAM role configuration. Existing environments receive actionable guidance to add the permissions. The feature is available in all AWS Commercial Regions that support SageMaker Studio.
read more →

Securing multi-tenant AI agents with AgentCore policies

🔒 This post shows how SaaS providers can use Amazon Bedrock AgentCore resource-based policies to control multi-tenant access to a shared AgentCore Runtime and Runtime endpoint. It walks through two tenant scenarios: cross-account access for Example Corp and VPC-restricted access for AnyCompany, demonstrating how to apply resource-level Allow and explicit Deny conditions. The article covers required IAM permissions, example policy files, and verification steps to ensure network- and identity-based constraints are enforced.
read more →

SageMaker Unified Studio supports IAM permissions boundaries

🔒 Amazon SageMaker Unified Studio now supports custom IAM permissions boundaries so organizations enforcing Service Control Policies (SCPs) can provision projects without changing their security posture. When creating a project, SageMaker provisions three IAM roles — a project user role, an Amazon Bedrock service role, and a Bedrock Lambda execution role — and administrators can specify a permissions boundary in the Tooling blueprint configuration. The boundary is attached to all three roles at creation, satisfying SCP requirements and limiting role capabilities while allowing automatic project provisioning across all supported AWS Regions.
read more →

AgentCore Identity supports customer-managed secrets

🔐 Amazon Bedrock AgentCore Identity now lets customers reference existing AWS Secrets Manager secret ARNs directly in Credential Providers. Previously, secrets were service-managed and created by AgentCore Identity, limiting tagging, CMK encryption, and governance controls. Customers can now create and manage secrets with their own policies and then reference the ARN without changing runtime behavior. This feature is GA in 14 AWS Regions.
read more →

AWS Organizations emits CloudTrail events for account changes

🔔 AWS Organizations now emits CloudTrail events to the management account when member accounts join or leave an organization, introducing two new events: AccountJoinedOrganization and AccountDepartedOrganization. The join event records method (Created or Invited) and timestamp, while the depart event records mode (Left, Removed, or Cleaned) and timestamp. Administrators can use these events with CloudWatch alarms or EventBridge rules to enable real‑time notifications and faster incident response.
read more →

Amazon Connect Customer adds tag-based access controls

🔒 Amazon Connect Customer now supports tag-based access controls for the agent login/logout report, allowing administrators to apply granular permissions to meet compliance and regulatory needs. Contact center admins can use resource tags to limit who can view login/logout data for specific agents—for example, tagging agents with Department:Customer Service to allow only that team's manager to view their login/logout details. The feature is available in all AWS commercial and AWS GovCloud (US-West) regions where Amazon Connect Customer is offered.
read more →

SageMaker adds catalog and governance for IAM domains

🛠️ Amazon SageMaker Unified Studio now adds business context, metadata, and data governance features for IAM-based domains. Customers can annotate AWS Glue Data Catalog tables with business names, descriptions, and README documentation, and use AI-generated metadata to automate cataloging. Teams can build business glossaries, define metadata form templates, and capture structured attributes like classification, retention, and ownership. These capabilities enable search, filtering by glossary or metadata fields, and access requests with automated Lake Formation permission grants, and are available in all regions where SageMaker Unified Studio is supported.
read more →

Automating identity lifecycle with AWS Directory APIs

🔒 AWS Managed Microsoft AD now supports CRUD operations on users and groups through the Directory Service Data APIs, accessible via the AWS CLI, APIs, and Management Console. This enables automation of identity lifecycle management and tighter security controls by integrating with services like Amazon GuardDuty, AWS Step Functions, and Amazon EventBridge. The blog demonstrates a practical workflow that detects unusual AD user behavior and triggers automated remediation such as disabling accounts and notifying stakeholders.
read more →

Why Amazon Bedrock AgentCore Chose Cedar Policies for Agents

🔒 Amazon explains how AgentCore Gateway enforces a centralized authorization layer between autonomous agents and external tools, treating the LLM as an untrusted actor. Policies are expressed in the open-source Cedar language for readability, bounded execution, and mathematical analyzability, enabling deterministic enforcement and formal verification during policy authoring and attachment. A neuro-symbolic workflow translates natural-language rules into Cedar, validates them with Cedar Analysis, and enforces decisions at runtime to constrain tool invocations and filter unavailable actions.
read more →

Agent AI Adoption Exposes Identity Gaps and Risks Now

⚠️Orchid Security's Identity Gap: Snapshot 2026 reveals that unseen, unmanaged identity elements now exceed visible ones, with 'identity dark matter' at 57% versus 43%. The report warns that rapid adoption of Agent AI amplifies risk because autonomous agents look for the most efficient access paths, often exploiting hard-coded or orphaned credentials and excessive privileges. Orchid urges strengthening identity and access management controls and using its readiness checklist to mitigate exposures.
read more →

Regional Routing for AWS Access Portals with Vanity Domains

🌐 AWS outlines how to present a single, brand-aligned vanity entry point (for example, aws.mycompany.com) in front of IAM Identity Center multi-Region access portals. The approach uses Amazon Route 53 latency-based routing, Application Load Balancer 302 redirects, and optional Amazon ARC Region switches for automated failover while TLS is managed through AWS Certificate Manager. Traffic is directed to the nearest healthy regional portal and the vanity domain does not persist in the browser address bar.
read more →

Amazon Connect: Agents Can View Own Evaluations Securely

🛡️ Amazon Connect Customer now offers a permission that lets agents access only their own performance evaluations directly in the Connect UI. Agents can search for contacts where they received evaluations, view evaluations alongside call recordings and transcripts, and submit an acknowledgment after review. Administrators can grant department-level contact visibility for investigations while preventing access to peers' evaluation data. The feature is available in all AWS regions where Amazon Connect Customer is offered.
read more →