< ciso
brief />
Tag Banner

All news with #iam tag

261 articles · page 3 of 14

AWS IAM Role Manager simplifies role provisioning

🔒 IAM Role Manager automates the creation and attachment of IAM roles as you build resources in supported AWS service consoles. When enabled, AWS provisions roles from managed templates or reuses suitable ones, letting you start services quickly while maintaining full visibility and control. Roles are ordinary IAM roles you can review, edit, or delete, and IAM Access Analyzer can later recommend least-privilege policies.
read more →

Amazon Bedrock adds IAM principal cost allocation

🔒 Amazon Bedrock now supports cost allocation by AWS Identity and Access Management (IAM) principal — including IAM users and roles — for model inference requests made through the bedrock-mantle endpoint. This extends existing support for the bedrock-runtime endpoint and enables customers to attribute inference costs to teams, projects, or applications using IAM principal tags. Activate IAM principal tags in the AWS Billing and Cost Management console to analyze costs in AWS Cost Explorer or include caller identity data in AWS Cost and Usage Report 2.0.
read more →

AWS IAM launches Account Access Manager feature

🔐 AWS Identity and Access Management (IAM) introduced Account Access Manager, simplifying assignment of IAM roles to workforce users and groups from AWS IAM Identity Center. Administrators can now manage role assignments centrally while retaining per-account role flexibility, using the AWS IAM console, SDKs, CloudFormation, and CDK. The feature consolidates permissions management, user awareness, and a single federation point at no additional cost.
read more →

A decade of AWS Managed Microsoft AD evolution

🔒 Over ten years, AWS Managed Microsoft AD evolved from a basic managed Microsoft Active Directory offering into a foundational enterprise identity service integrated across more than 20 AWS services. The service reduced operational overhead by handling domain controllers, HA, backups, patching, and replication while adding features like schema extensions, gMSA, multi-Region replication, and CRUD APIs. Recent additions include Hybrid Edition, self-service edition upgrades, and integrations for database, file, and remote-access authentication.
read more →

Amazon Cognito added to Agent Toolkit skills

🔧 The Amazon Cognito (aws-auth) skill is now included in the Agent Toolkit for AWS, enabling AI coding agents to set up, configure, secure, and troubleshoot Amazon Cognito using best-practice workflows. The skill supports user pools, app clients, OAuth 2.0 flows, token and JWT authorizer management, passkey/WebAuthn enrollment, threat protection, Lambda triggers, and identity pools. When used with the AWS MCP Server, commands run with IAM guardrails and CloudTrail audit logging; it also works standalone via the AWS CLI.
read more →

Securing Amazon S3: Identify and Remediate Over‑Permissions

🔒 This post explains how to detect and remediate over‑permissioned Amazon S3 buckets across single‑ or multi‑account AWS environments. It outlines a five‑phase workflow—setup, detection, remediation, continuous monitoring, and cleanup—while recommending AWS Config, Security Hub, EventBridge, IAM Access Analyzer, and Lambda‑based scanning scripts. The guidance focuses on methodology and customization for security engineers, cloud architects, and DevOps teams.
read more →

OpenSearch UI adds network access controls

🔒 Amazon OpenSearch Service now supports network access controls for OpenSearch UI applications, enabling administrators to restrict access to approved networks using IAM condition keys like aws:SourceVpce, aws:SourceVpc, and aws:SourceIp. You can enforce restrictions via identity-based policies, VPC endpoint policies, and organization-wide resource control policies (RCPs), which can block off-network users before authentication. This feature is available in all Regions where OpenSearch UI is offered.
read more →

Amazon Cognito adds self-service provisioned limits

🔒 Today Amazon Cognito launches provisioned limits in the console to let teams self-service authentication rate adjustments in minutes. The feature separates an account-level maximum (managed via Service Quotas) from a provisioned limit you pay for and control in the Amazon Cognito console, enabling rapid scaling for events like Black Friday. It supports granular RPS adjustments, programmatic APIs, and cost optimization by billing only for provisioned capacity above defaults.
read more →

AWS Identity Center makes account management optional

🔒 AWS IAM Identity Center now lets administrators choose whether to enable AWS account access management when creating a new instance. This option permits using Identity Center solely for managing access to AWS applications, without provisioning access to AWS accounts. The setting is available during initial configuration, does not affect existing instances, and can be changed later via instance settings or the UpdateInstance API. The capability is available in all Regions where IAM Identity Center is offered.
read more →

AWS Organizations adds account quota visibility in ServiceQuotas

🔍 AWS Organizations customers can now view their maximum account quota and current utilization directly in AWS Service Quotas. This eliminates the need to contact AWS Support or account teams to determine account limits. Administrators can check quotas from the management account via the Service Quotas console or the GetServiceQuota API. The feature is available now in US East (N. Virginia).
read more →

AI Elevates Need for Cybersecurity Fundamentals

🔒 AI-driven tools are exposing long-standing security gaps while accelerating familiar attack techniques. Experts stress that core practices—identity management, patching, configuration hygiene, multifactor authentication, and zero-trust—remain essential and must be applied consistently. AI increases speed, scale, and customization of attacks, but does not eliminate the need for human oversight, judgment, and accountability.
read more →

IAM Policy Simulator integrated into IAM console

🛠️ AWS has updated the IAM Policy Simulator with three key changes: it is now integrated into the IAM console, it supports testing of service control policies (SCPs), and it offers greater modeling flexibility for realistic scenarios. The simulator replaces the standalone site and lets you include SCPs to evaluate interactions with identity and resource policies. New options allow excluding specific policies to model removal scenarios, and cross-account simulations report per-policy decisions with matched statements shown for denials. These enhancements aid automation of policy unit tests, detection of over-permissive access, and validation of guardrails across regions where the simulator is available.
read more →

AlloyDB adds IAM group authentication for enterprises

🔒 Google Cloud announced preview support for Identity and Access Management (IAM) group authentication in AlloyDB, extending an identity-driven, passwordless access model to enterprise database workloads. The feature aligns AlloyDB with Cloud SQL by enabling group-based access controls to reduce individual account sprawl, simplify on- and off-boarding, and improve auditing. It also helps secure AI agents by ensuring actions map to user identities and limiting privilege escalation.
read more →

IAM Identity Center adds multi‑Region directory replication

🔁 IAM Identity Center now replicates identities and entitlements from the primary AWS Region to additional Regions when using the Identity Center directory as the identity source. This extends prior multi‑Region support for organization instances that used external identity providers to those using the Identity Center directory, improving resilience and enabling deployment closer to users and for data residency. The feature requires a multi‑Region customer managed KMS key and is available in the 17 enabled‑by‑default commercial Regions; standard KMS charges apply.
read more →

Amazon Neptune adds tag-based access control

🔒 Amazon Neptune now supports tag-based access control (TBAC) for IAM, enabling the use of AWS resource tags and IAM principal tags as conditions in IAM policies and Service Control Policies to govern data-plane access. TBAC lets administrators restrict neptune-db:* actions to clusters whose tags match principal tags, reducing lateral access risks in shared VPCs and supporting federated identities via SAML or OIDC session tags. The feature is available in all Regions running Neptune and requires engine version 1.2.0.0+ with IAM authentication enabled.
read more →

Hardening Google Cloud access with IAM conditions

🔐 In Google Cloud, IAM enforces the Principle of Least Privilege by combining predefined and custom roles with Allow and Deny policies across resource hierarchies. When resource-level bindings are not possible, IAM conditions let you scope broad roles to specific APIs, services, MCP servers, tools, or time windows. Use conditions alongside Deny policies to surgically remove excessive permissions and strengthen defense-in-depth.
read more →

AWS Marketplace adds India seller signature management

📝 AWS Marketplace now lets India-based sellers upload and manage their seller signatures directly through AWS Partner Central, replacing the prior manual email submission process. This centralized flow consolidates GSTIN registration and signature management for sellers transacting in India. Uploaded signatures are securely stored and used for buyer tax invoices, with automated real-time validation and an at-a-glance tax summary showing verification status. Sellers receive email notifications on verification outcomes and can resubmit if rejected using provided rejection reasons.
read more →

Security Priorities and Risks in the AI Era

🔐 At a recent Information Security Day seminar, white-hat hacker and Steelion CEO Park Chan-am outlined how AI is accelerating attacks and reshaping security priorities. He emphasized that access control, supply chain security, and human verification remain central even as AI shortens vulnerability discovery from weeks to hours. Park warned that AI agents and local testing environments widen attack surfaces and urged new approaches to vulnerability prioritization and behavioral defenses.
read more →

AWS CloudTrail adds UserIdentity network filters

🔍 Today AWS announced enhanced CloudTrail filtering for VPC endpoint network activity events, allowing selectors that filter logs by the IAM user identity making API calls. This update lets customers log only relevant events — for example, access denied actions from identities outside a trusted list — reducing logging noise and cost. The feature supports console, CLI, and SDK access and is available in all Regions that support CloudTrail network activity events.
read more →

Global IAM Data Governance Tags for BigQuery

🔒 This post introduces the preview of IAM data governance tags for BigQuery column-level security. Built on Google Cloud Resource Manager tags with purpose=DATA_GOVERNANCE, these tags are global, support hierarchical classification up to five levels, and are replicated for disaster recovery. The article explains creating tag keys/values, attaching tags to columns via JSON or SQL, and defining regional BigQuery data policies for masking or raw access. It highlights decoupled governance, regional policy enforcement, and layered security requirements.
read more →