#aws-identity-and-access-management
マ????これかなりアツいのでは????

Centrally manage root access in AWS Identity and Access Management (IAM) - AWS
Centrally manage root access in AWS Identity and Access Management (IAM) - AWS
Discover more about what's new at AWS with Centrally manage root access in AWS Identity and Access Management (IAM)
aws.amazon.com
November 15, 2024 at 10:11 PM
🎉 Finally, you can centrally manage root access in IAM and perform privileged tasks across member accounts.

This feature helps with compliance and reduces the need for MFA.

#AWS #IAM #CentrallyManageRootAccess
Centrally manage root access in AWS Identity and Access Management (IAM) - AWS
Discover more about what's new at AWS with Centrally manage root access in AWS Identity and Access Management (IAM)
zpr.io
November 17, 2024 at 2:37 PM
ChatGPT will soon replace engineers they say.
October 21, 2024 at 1:43 PM
The AWS MCP Server now supports cross-account and cross-role access

Today, AWS announced cross-account and cross-role access for the AWS Model Context Protocol (MCP) Server, part of the https://aws.amazon.com/products/developer-tools/agent-toolkit-for-aws/. This feature ...

#AWS #AwsDeveloperTools
The AWS MCP Server now supports cross-account and cross-role access
Today, AWS announced cross-account and cross-role access for the AWS Model Context Protocol (MCP) Server, part of the https://aws.amazon.com/products/developer-tools/agent-toolkit-for-aws/. This feature allows developers using AI coding agents like Kiro, Claude Code, or Codex to work across multiple AWS accounts and AWS Identity and Access Management (IAM) roles within a single session, with no restarts required. Previously, switching profiles required stopping the AI coding session, updating local AWS credentials, and restarting the MCP server for every account change. Now, AI agents using the AWS MCP Server can specify a profile on each command, allowing users to switch between accounts and roles seamlessly. Cross-account access helps developers move faster across multi-account environments. For example, a DevOps engineer can query CloudWatch logs across production and staging accounts to diagnose a performance issue, or an application developer can update a Lambda configuration in one account and adjust an S3 bucket policy in another, all within the same conversation. Each request specifies which profile to use, so there is no risk of commands reaching the wrong account. To get started, see https://docs.aws.amazon.com/agent-toolkit/latest/userguide/multi-account-access.html in the Agent Toolkit for AWS user guide. The AWS MCP Server is available in the US East (N. Virginia) and Europe (Frankfurt) Regions.
aws.amazon.com
June 5, 2026 at 6:05 PM
50 AWS IAM (Identity and Access Management) Interview questions and answers:

https://tapurl.to/amazoniam
September 26, 2026 at 1:18 AM
Awesome work by the folks at AWS that implemented this! AWS now prevents OIDC misconfigurations with many popular third-parties. docs.aws.amazon.com/IAM/latest/U...

This is an issue I described here: www.wiz.io/blog/avoidin...
Identity-provider controls for shared OIDC providers - AWS Identity and Access ManagementIdentity-provider controls for shared OIDC providers - AWS Identity and Access Management
For recognized shared OIDC providers, IAM requires explicit evaluation of specific claims in role trust policies to validate that only authorized federated identities can assume roles.
docs.aws.amazon.com
June 9, 2025 at 6:55 PM
What AWS services do you think are underrated? I asked developers what their favorite hidden gems are! 💎

Underrated services highlighted include:
⭐️ AWS Systems Manager
📝 Amazon Textract
👥 AWS Identity and Access Management (IAM)
⚡️ Amazon EventBridge
🔐 Amazon Cognito

Do you agree?
November 25, 2024 at 6:42 PM
I don’t Ian is on Bluesky yet, and I don’t want you to miss this blog post! Ian McKay breaks down how RCPs are useful and some limitations.

onecloudplease.com/blog/resourc...
Resource Control Policies: Closing the data perimeter gap – One Cloud Please
It's pre:Invent season, and one of the most consequential identity and access management features was just released by the identity team at AWS. Resource Control Policies, a strong tool for establishi...
onecloudplease.com
November 17, 2024 at 6:00 PM
AWSのIAMでAction指定するところ、`sns:Publish` でも `SNS:publish` でも大文字小文字区別しないので一緒、というのをAWS歴10数年にして初めて知った docs.aws.amazon.com/ja_jp/IAM/la...
IAM JSON ポリシー要素Action - AWS Identity and Access ManagementIAM JSON ポリシー要素Action - AWS Identity and Access Management
IAM JSON ポリシー言語の Action 要素を記述します。
docs.aws.amazon.com
April 18, 2024 at 6:57 AM
identity and access management? With AWS IAM…
March 25, 2026 at 11:56 PM
A targeted campaign exploited Server-Side Request Forgery (SSRF) vulnerabilities in websites hosted on AWS EC2 instances to extract EC2 Metadata, which could include Identity and Access Management (IAM) credentials from the IMDSv1 endpoint.
Hackers target SSRF bugs in EC2-hosted sites to steal AWS credentials
A targeted campaign exploited Server-Side Request Forgery (SSRF) vulnerabilities in websites hosted on AWS EC2 instances to extract EC2 Metadata, which could include Identity and Access Management (IAM) credentials from the IMDSv1 endpoint.
www.bleepingcomputer.com
April 9, 2025 at 8:59 PM
Hi James — LocalStack emulates IAM roles, policies, and more[1]. We also support strict IAM enforcement, so you can test whether your IAM policies are working as expected [2].

[1]: docs.localstack.cloud/aws/services...
[2]: docs.localstack.cloud/aws/capabili...
Identity and Access Management (IAM)
Get started with AWS Identity and Access Management (IAM) on LocalStack
docs.localstack.cloud
July 13, 2025 at 7:01 AM
Keycloak — Secure authentication and access control made simple

⭐ Stars: 32,909
🔗 Forks: 8,062
⏩ Last commit: Feb 19, 2026
⌛ First commit: Jul 2, 2013
Keycloak: Open Source Alternative to Auth0, WorkOS and AWS Cognito
Comprehensive open source identity management solution offering single sign-on, social login, and fine-grained authorization for applications and services.
openalternative.co
February 20, 2026 at 11:01 PM
AWS IAM outbound identity federation now supports interface VPC endpoints for OIDC discovery
AWS Identity and Access Management (IAM) outbound identity federation now supports Amazon Virtual Private Cloud (VPC) endpoints for the OpenID Connect (OIDC) discovery APIs. You can now access the OIDC discovery metadata and JSON Web Key Set (JWKS) verification key endpoints from within your VPC using AWS PrivateLink, without requiring traffic to traverse the public internet. IAM outbound identity federation eliminates the need to use long-lived credentials when your AWS workloads access external services. Instead, your workloads request short-lived JSON Web Tokens (JWTs) from AWS Security Token Service (AWS STS). External services verify these tokens using public verification keys and metadata available at OIDC discovery endpoints. Previously, the OIDC discovery endpoints were only reachable over the public internet, so a verifying workload running in a VPC without internet access could not retrieve them. With this launch, you can create an interface VPC endpoint to reach these endpoints privately, keeping the verification key retrieval traffic within the AWS network. This capability helps you meet network security requirements for workloads that operate in VPCs with restricted internet access, while still enabling external services to verify JWTs. This feature is available in all commercial AWS Regions, the AWS GovCloud (US) Regions, and China Regions. There is no additional charge for this feature beyond standard AWS PrivateLink pricing. To learn more, see the IAM User Guide.
dlvr.it
September 25, 2026 at 9:48 PM
🆕 AWS IAM outbound identity federation now supports VPC endpoints for OIDC discovery, enabling private access to OIDC metadata and JWKS keys within VPCs without public internet access, enhancing network security. Available in all commercial regions, no…

#AWS #AwsIdentityAndAccessManagement #AwsIam
AWS IAM outbound identity federation now supports interface VPC endpoints for OIDC discovery
AWS Identity and Access Management (IAM) outbound identity federation now supports Amazon Virtual Private Cloud (VPC) endpoints for the OpenID Connect (OIDC) discovery APIs. You can now access the OIDC discovery metadata and JSON Web Key Set (JWKS) verification key endpoints from within your VPC using AWS PrivateLink, without requiring traffic to traverse the public internet. IAM outbound identity federation eliminates the need to use long-lived credentials when your AWS workloads access external services. Instead, your workloads request short-lived JSON Web Tokens (JWTs) from AWS Security Token Service (AWS STS). External services verify these tokens using public verification keys and metadata available at OIDC discovery endpoints. Previously, the OIDC discovery endpoints were only reachable over the public internet, so a verifying workload running in a VPC without internet access could not retrieve them. With this launch, you can create an interface VPC endpoint to reach these endpoints privately, keeping the verification key retrieval traffic within the AWS network. This capability helps you meet network security requirements for workloads that operate in VPCs with restricted internet access, while still enabling external services to verify JWTs. This feature is available in all commercial AWS Regions, the AWS GovCloud (US) Regions, and China Regions. There is no additional charge for this feature beyond standard AWS PrivateLink pricing. To learn more, see the IAM User Guide.
aws.amazon.com
September 25, 2026 at 10:10 PM
IAM (Identity and Access Management): controla quién puede hacer qué dentro de AWS. Por ejemplo, define qué programa o usuario puede leer una tabla o crear un servidor. Si IAM se ve afectado, puede haber fallos al intentar crear o modificar permisos y usuarios.
October 20, 2025 at 10:55 AM
AWS IAM Identity Center organization instances now support customer-managed KMS keys for encryption at rest

IAM Identity Center now supports customer-managed AWS Key Management Service (KMS) keys for encrypting workforce identity data, including user and group attri...

#AWS #AwsIamIdentityCenter
AWS IAM Identity Center organization instances now support customer-managed KMS keys for encryption at rest
IAM Identity Center now supports customer-managed AWS Key Management Service (KMS) keys for encrypting workforce identity data, including user and group attributes. While AWS-owned keys are used by default, customer-managed keys (CMKs) provide granular control over identity data access, enhancing security and compliance capabilities. IAM Identity Center helps you securely create, or connect, your workforce identities and manage their access centrally across AWS applications and accounts. You create a CMK and manage its lifecycle and usage permissions in AWS KMS. You can configure the CMK in your IAM Identity Center instance either while enabling a new organization instance or on an existing one. You can then use AWS CloudTrail to monitor and audit the usage of your CMK for access to identity data in IAM Identity Center. Support for CMKs in organization instances of IAM Identity Center is now available for access to accounts and https://docs.aws.amazon.com/singlesignon/latest/userguide/awsapps-that-work-with-identity-center.html in all https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/ where IAM Identity Center is available. Standard AWS KMS https://aws.amazon.com/kms/pricing/ apply to storing and using CMKs. IAM Identity Center is provided at no additional cost. To learn more about IAM Identity Center, visit the https://aws.amazon.com/iam/identity-center/. To get started with using CMKs, please refer to the IAM Identity Center https://docs.aws.amazon.com/singlesignon/latest/userguide/encryption-at-rest.html.
aws.amazon.com
September 23, 2025 at 7:05 PM