Security, Identity, & Compliance
Recent questions
see all- We have configured Amazon RDS with High Availability (Multi-AZ) and a DR region using a Read Replica. We are planning to enable AWS Secrets Manager password rotation with a 90-day rotation schedule. ...
- We are planning to use Amazon Bedrock (eu-west-1, Ireland) with the EU Anthropic Claude Sonnet 5 inference profile to analyse anonymised research data. AWS documentation states that Bedrock does not ...
- I have shut down my business that uses AWS and I have tried hard to delete all resources. But two main items are, it seems, impossible for me to delete. - Elastic IP: 34.195.183.124 - cannot be dele...
- Summary I've configured PingFederate 13.0.3 as an external SAML 2.0 identity provider for AWS IAM Identity Center. The identity source change was accepted successfully by AWS ("You successfully chang...
- Region: App Studio us-west-2, IAM Identity Center us-east-1 Note: Understanding App Studio is only available in Oregon I did switch Region to Oregon and the setup accepted my IAM group etc. Logged in...
- We remediated CVE-2026-45490 (.NET SDK Elevation of Privilege) and CVE-2026-45591 (ASP.NET Core Denial of Service) across EC2 fleets in two separate AWS accounts, both in us-east-2. In both accounts, ...
- I opted into UAE (me-central-1) on a new-ish account and can't launch compute there. - ecs:CreateCluster → ThrottlingException: "Rate exceeded" (every call, 24h+, even single calls after long idle). ...
- Here's a public-safe version for re:Post — account ID, IAM ARN, and any account-identifying details are redacted: --- **Title:** AWS FinOps Agent (Preview) — `CreateIntegration` (Slack) returns 403 ...
- How does the AWS DevOps Agent handle incident resolution across multiple AWS accounts in an AWS Organizations setup — can it correlate alarms from a shared monitoring account with resources in spoke w...
- Hi there, I am getting a SAML login failure ("Response contains invalid principal tag value... Select a role") whenever a user matches more than one Application Entitlement group - same stack or diff...
- Hello, I requested Amazon SES production access for a B2B timesheet management app and was denied by Trust & Safety after providing additional details. I'm preparing to appeal and want to know if impr...
- I'm looking for confirmation on whether my understanding is correct that AWS WAF (when attached to an Application Load Balancer) cannot enforce a rule that blocks requests whose body size exceeds a sp...
- Hi AWS community, My personal AWS account is restricted due to verification issues. I have submitted a support ticket, which has now been unassigned for over 4 weeks. Is this expected? Is there anythi...
- SUBJECT: AWS IoT Core rejects MQTT-over-WebSocket (SigV4) CONNECT with AUTHORIZATION_FAILURE despite verified-correct IAM policy, trust policy, and valid STS credentials from Cognito Identity Pool --...
- I am unable to create Kiro subscriptions for any users in my AWS Organization. This issue has persisted for over 72 hours since organization creation, and all configuration requirements have been veri...
- Hello, We are investigating a change in behavior in AWS IoT JITP (Just-In-Time Provisioning). For several years, our JITP template worked correctly when a device was reprovisioned with a new certific...
- Submitted a production access request 2026-07-01 for a low-volume transactional sender (personalized daily email digest, double opt-in only). case ID (**************) Answered AWS's follow-up quest...
- I submitted a request to move my Amazon SES account out of the sandbox over a week ago and have not received any response — no approval, no rejection, and no follow-up questions. I also replied to th...
Recent Knowledge Center content
see allRecent articles
see allTony BEXPERT
published 2 days ago0 votes27 views
Amazon GameLift Streams now supports assigning an IAM role to a stream session, enabling your application to securely access resources in your AWS account, such as Amazon S3 buckets and DynamoDB table...Sagar GandhaEXPERT
published 8 days ago0 votes70 views
AWS DevOps Agent charges per agent-second with no built-in spending cap or alert mechanism. This article walks through setting up a CloudWatch metric math alarm that sums daily consumption across all ...KartikEXPERT
published 11 days ago0 votes120 views
AWS DevOps Agent's release readiness review is native to GitHub and GitLab, but not to BitBucket Cloud. This article covers a bridge pattern (Amazon Bedrock AgentCore Gateway, Amazon Cognito, and a si...- AWS OFFICIALUpdated 11 days ago0 votes788 viewsLearn how AWS DevOps Agent investigates your operational issues autonomously in the AWS Support Center Console, delivering root cause analysis and reducing resolution time.
LokeshEXPERT
published 11 days ago1 votes80 views
Enterprise organizations running 1000+ AWS accounts need AWS DevOps Agent to trace root causes across account boundaries — from workload accounts through shared networking and centralized logging. Thi...- AWS OFFICIALUpdated 6 days ago0 votes167 viewsYou can use Kiro CLI with the AWS Model Context Protocol (MCP) Server to query AWS DevOps Agent investigations and review root cause findings. These tools can also help you provide additional context ...
David VEXPERT
published 12 days ago4 votes315 views
AWS doesn't offer native per-user spend caps for Amazon Bedrock. This guide provides a production-ready architecture for enforcing per-user monthly budget limits on Bedrock for Identity Center (SSO) u...- AWS OFFICIALUpdated 11 days ago0 votes233 viewsLearn how to route AWS Incident Detection and Response alarms to AWS DevOps Agent for instant, autonomous investigation when an alarm activates.
Rob_HEXPERT
published 14 days ago0 votes243 views
When enforcing zero data retention on Amazon Bedrock with an SCP, there's an important prerequisite: new accounts default to inherit (not none). The SCP prevents changing the mode, but it doesn't set ...KinjanEXPERT
published 19 days ago0 votes64 views
Account closure does not automatically clean up AWS Security Incident Response (SIR). This article explains the SIR-specific steps to take before closing accounts: removing them from OU-based scope, d...Ram AchantaEXPERT
published 20 days ago2 votes114 views
Organizations scaling AWS workloads across EC2, EMR, containers, and Lambda face growing vulnerability counts that overwhelm application teams. Challenges include EMR on EC2 vulnerability multiplicati...Akhilesh-Sr TAMEXPERT
published 20 days ago0 votes58 views
Enterprises upgrading their AWS Lake Formation cross-account sharing to Version 5 may get blocked from granting data access across accounts breaking cross-account data lake workflows. This article pro...- AWS OFFICIALUpdated 20 days ago1 votes238 viewsThis article shows how to troubleshoot faster with four AWS AI-powered tools, including Amazon Q Developer, Kiro CLI, AWS DevOps Agent, and AI-enhanced troubleshooting in the AWS Support Center.
published 22 days ago0 votes77 views
Parts 1–3 covered runtime failures. This one tackles the opposite: change-time failures that pass every pipeline check yet still reach production — because staging drifts from production and tests jud...published 22 days ago0 votes74 views
To show builders how to compose a single scheduled custom SRE agent — using AWS DevOps Agent's own custom-agents capability (June 2026) — that runs a daily Start-of-Day Readiness SOP and answers one b...NiharSUPPORT ENGINEER
published a month ago0 votes184 views
This article explains how to enable and configure the AWS Kiro Enterprise subscription for organizations that use a cross-account STS AssumeRole model, where IAM users log in to a central identity acc...Kumar ShubhamEXPERT
published a month ago0 votes122 views
AWS DevOps Agent's Topology, the map of resources and relationships it consults during incident investigations, is built partly from resource tags. Inconsistent or missing tags slow the agent down. Th...Kumar ShubhamEXPERT
published a month ago0 votes268 views
AWS DevOps Agent now offers headless access via the Model Context Protocol (MCP), letting developers invoke production observability and root-cause investigations directly from Kiro, Claude Code, Curs...
Recent selections
see allAWS OfficialMODERATOR
published 7 days ago0 votes59 views
This spotlight on AWS Certificate Manager (ACM) equips you with the skills and troubleshooting tips to get the most out of a powerful service.- AWS OFFICIALUpdated 3 months ago1 votes223 viewsAWS Official content is created by a team of technical experts, professional writers, and editors within AWS. They work together to make sure that the information is clear, comprehensive, and aligned ...
AWS OfficialMODERATOR
published 3 months ago0 votes197 views
This spotlight on AWS IAM equips you with skills and troubleshooting best practices to secure and manage access to your AWS resources effectively.AWS OfficialMODERATOR
published 10 months ago1 votes353 views
This spotlight on Amazon Cognito equips you with the skills and troubleshooting best practices to get the most out of this cost effective service.AWS OfficialEXPERT
published 2 years ago0 votes1K views
This spotlight on IAM equips you with the skills and troubleshooting tips to get the most out of a powerful service.- AWS OFFICIALUpdated 11 days ago11 votes35K viewsThe AWS Trust & Safety Center provides curated knowledge of AWS resources that can assist you in your cloud journey.
Osvaldo MarteEXPERT
published 2 years ago2 votes18.7K views
This selection focuses on the essential AWS networking services, providing a comprehensive overview of tools and technologies available to build and manage secure, scalable, and high-performing networ...Antonio LagrotteriaEXPERT
published 2 years ago4 votes28.3K views
A selection of architectural patterns and tips to leverage secure cross-account APIs, showing ingress, egress and inspection reference architecturesJonathan_DEXPERT
published 3 years ago4 votes12.4K views
Do you have critical workloads running in AWS? Review these handpicked resources to find ways to ensure your applications are resilient to failures.- AWS OFFICIALUpdated 3 years ago0 votes105 viewsThis selection includes content and solutions supporting FSI related compliance and requirements covering security, immutable storage, and general guidance.
- AWS OFFICIALUpdated 3 years ago0 votes274 viewsAs a best practice, AWS recommends that you use AWS Identity and Access Management (IAM) roles instead of IAM users with long-term credentials such as access keys.
- AWS OFFICIALUpdated 3 years ago0 votes64 viewsAccelerate your business transformation goals with a managed service that combines compute, network and storage capabilities in a fully supported, ready-to-run service from VMware and AWS.
- AWS OFFICIALUpdated 3 years ago0 votes8.2K viewsAre you getting 403 Access Denied errors with your Amazon Simple Storage Service (Amazon S3) operations? Review this list of handpicked resources to identify the root cause and troubleshooting instruc...
Riku_Kobayashi
EXPERTGary Mclean
EXPERTsecondabhi_aws
EXPERTOleksii Bebych
EXPERTGreg
EXPERTKidd Ip
EXPERTOsvaldo Marte
EXPERTBehrens, Isaac
EXPERTSedat SALMAN
EXPERTAdeleke Adebowale .J.
EXPERTFlorian Turnwald
EXPERTTushar Jagdale
EXPERTMatt Barbieri
EXPERTAWS-User-alantam
EXPERTIndranil Banerjee AWS
EXPERTTakahito Iwasa
EXPERTMassimilianoAWS
EXPERTGK
EXPERT
