Security, Identity, & Compliance
Recent questions
see all- I've noticed that Amazon SES can give very different results for production access requests. Some accounts are approved automatically, while others with properly configured domains and clear use cases...
- I am trying to understand if it is possible to get a true single sign-on user experience when using an IAM identity center instance (service provider) with Microsoft Entra ID as the external identity ...
- Amazon Inspector Code Security (GitHub integration, ap-northeast-1) flagged 241 "CWE-89 - SQL Injection" findings in a CodeIgniter 4 PHP application. On manual review, every sampled instance uses Code...
- I don't understand why Amazon SES can automatically approve some accounts while new customers with properly configured domains are sent to manual review or rejected. If an account is approved automati...
- Hi everyone, I’ve been reading some discussions on the forum about automatic approvals for production access, and I’d like to understand how this works. I’ve tried several times to get production acc...
- Hello AWS Team & Community Managers, I am requesting assistance to route an open SES Support ticket to the Trust & Safety review team. Our application for SES Production Access was submitted on July...
- I chose Amazon SES because AWS has a strong reputation for stable infrastructure and reliable business services. A company can accept a strict production access process when it believes the same stand...
- I am using Forgejo 15.0.6 LTS with an AWS IAM OIDC provider configured for: ```text Issuer: https://git.sakthisanthosh.in/api/actions Audience: sts.amazonaws.com Subject: repo:ssanumand/lad-forgejo-a...
- I'm federating a GCP service account into AWS via Workload Identity Federation (no static AWS access keys) using `sts:AssumeRoleWithWebIdentity`, and every attempt fails with: An error occu...
- QUESTIONS 1. Is the ~10 second wait expected? The documentation states a 2 second timeout. 2. Is resolving with an empty value (instead of throwing) an intended outcome? If so, under what conditi...
- I'm getting SubscriptionRequiredException ("The AWS Access Key Id needs a subscription for the service") when calling Amazon Textract's DetectDocumentText API, and I've ruled out the usual causes: - ...
- I am implementing custom logic in Lambda to detect malicious clients. I want to identify and block malicious scripts/bots. WAF rules seem to a good fit. Would using online databases help? Should I jus...
- Hello, I received an email from AWS confirming that my request for EC2 access in the US East (N. Virginia) region has been validated. However, I still cannot launch any EC2 instance, including t3.mi...
- Anytime we save our WAF Web ACL's rules we're getting this error: "ValidationException 1 validation error detected: Value '{}' at 'associationConfig.challengeJavascriptSdkInjection' failed to satisfy ...
- Last month I had a DevOps Agent Enterprise Support Credit $5709 in my Organization account and it was expired on 31st July 2026 and we did not use it anymore and not previouly use the service. Now I...
- Hi AWS Community & Moderators, I am facing an issue with my AWS account verification. Every time I try to submit my details, I get a red error message. I created a support case for this, but it has...
- We have a Windows Forms desktop application in which users authenticate through an Amazon Cognito user pool. After signing in, the application must access specific Amazon S3 buckets or prefixes based ...
- Does Amazon Quick Desktop work with AWS IAM Identity Center? [Documentation](https://docs.aws.amazon.com/quick/latest/userguide/desktop-enterprise-setup.html) doesnt cover this
Recent Knowledge Center content
see allRecent articles
see allJiwon JungEXPERT
published 3 days ago0 votes42 views
A member account needs to be migrated to another AWS Organization. This account consumes resources shared by another account through AWS RAM. Because organization-scoped resource shares are automatica...Lucky IkaniSUPPORT ENGINEER
published 4 days ago0 votes70 views
I want to use multiple AWS Client VPN endpoints in different AWS accounts with the same Microsoft Entra ID (Azure AD) tenant for SAML authentication. When I create a second enterprise application in E...SapirEXPERT
published 4 days ago2 votes91 views
A step-by-step guide to connecting AWS DevOps Agent to a self-managed, privately hosted GitLab using a Private Connection over Amazon VPC Lattice - so you can have the agent investigate your repositor...Vamsi KrishnaEXPERT
published 6 days ago0 votes93 views
This article guides AWS Enterprise Support customers in education and government on how to strengthen their security posture using four AWS capabilities — Security Agent (prevent), Security Hub Unifie...Chirag_RSUPPORT ENGINEER
published 6 days ago0 votes92 views
This article will help customers using AWS Devops Agent with resources in Azure to integrate the Azure Devops/Cloud environment to have a streamlined tool.Manish MishraEXPERT
published 8 days ago0 votes136 views
You DM the bot in Teams (or @mention it in a channel). DevOps Agent responds directly in the conversation. If it kicks off an investigation, the results come back in the same thread when it's done. Fo...- AWS OFFICIALUpdated 10 days ago0 votes99 viewsIf you build or operate a service on AWS where users can share, generate, process, distribute, or store imagery, you might encounter non-consensual intimate imagery (NCII) or other forms of image-base...
Lucky IkaniSUPPORT ENGINEER
published 13 days ago3 votes164 views
I created a cross-account AWS Transit Gateway VPC attachment and it was accepted, but the attachment transitioned to a "failed" state instead of "available."Manish MishraEXPERT
published 14 days ago0 votes184 views
Chat and Kick-off DevOps agent investigation with context from Slack Channel. Allows multiple engineers to collaborate with DevOps Agent on the same incident thread simultaneouslyNate LeeSUPPORT ENGINEER
published 14 days ago2 votes210 views
Step-by-step guide to enable VPN BGP Logging on AWS Site-to-Site VPN, verify logs in CloudWatch, set up AWS DevOps Agent, and use natural language to analyze BGP session issues automatically.NiharSUPPORT ENGINEER
published 18 days ago0 votes111 views
Customers signing in to Kiro via app.kiro.dev using IAM Identity Center are unexpectedly redirected to aws.amazon.com/q/developer/. This occurs when the Kiro Sign-In application in IAM Identity Center...- AWS OFFICIALUpdated 19 days ago0 votes99 viewsThis article explains the domain name dispute resolution process and the options that are available to you for domain names that you register through Amazon Route 53.
Usama AshrafEXPERT
published 19 days ago6 votes142 views
Cannot Delete Permission Set: Removing Orphaned ApplicationProfile Associations Before Permission Set DeletionManish MishraEXPERT
published 21 days ago0 votes131 views
AWS DevOps Agent can investigate incidents autonomously, but it doesn't have a native Jira integration. This article shows how to connect the two bidirectionallyVinuthna KorinniEXPERT
published 24 days ago0 votes206 views
A step-by-step guide for separating production workloads from your AWS management account by migrating to a new organizationWAZEXPERT
published 25 days ago0 votes125 views
Part 3 of a three-part series mapping the OWASP Top 10 for Agentic Applications 2026 to AWS security controls. This final part covers the system's dynamics once agents persist state and act autonomous...WAZEXPERT
published 25 days ago0 votes123 views
Part 2 of a three-part series mapping the OWASP Top 10 for Agentic Applications 2026 to AWS security controls. This part covers what the agent runs at runtime: ASI02 (tool misuse and abuse), ASI04 (ag...Rodrigo ReyesSUPPORT ENGINEER
published 25 days ago0 votes149 views
On June 15, 2026, AWS WAF added AI traffic monetization, a Bot Control capability that lets content and API providers charge AI bots and agents for access to protected resources directly at the edge. ...
Recent selections
see allAWS OfficialMODERATOR
published a month ago0 votes205 views
This spotlight on AWS Certificate Manager (ACM) equips you with the skills and troubleshooting tips to get the most out of a powerful service.- AWS OFFICIALUpdated 4 months ago1 votes281 viewsAWS Official content is created by a team of technical experts, professional writers, and editors within AWS. They work together to make sure that the information is clear, comprehensive, and aligned ...
AWS OfficialMODERATOR
published 4 months ago0 votes241 views
This spotlight on AWS IAM equips you with skills and troubleshooting best practices to secure and manage access to your AWS resources effectively.AWS OfficialMODERATOR
published a year ago1 votes403 views
This spotlight on Amazon Cognito equips you with the skills and troubleshooting best practices to get the most out of this cost effective service.AWS OfficialEXPERT
published 2 years ago0 votes1K views
This spotlight on IAM equips you with the skills and troubleshooting tips to get the most out of a powerful service.- AWS OFFICIALUpdated 10 days ago14 votes37.9K viewsThe AWS Trust & Safety Center provides curated knowledge of AWS resources that can assist you in your cloud journey.
Osvaldo MarteEXPERT
published 2 years ago2 votes18.7K views
This selection focuses on the essential AWS networking services, providing a comprehensive overview of tools and technologies available to build and manage secure, scalable, and high-performing networ...Antonio LagrotteriaEXPERT
published 2 years ago4 votes28.4K views
A selection of architectural patterns and tips to leverage secure cross-account APIs, showing ingress, egress and inspection reference architecturesJonathan_DEXPERT
published 3 years ago4 votes12.5K views
Do you have critical workloads running in AWS? Review these handpicked resources to find ways to ensure your applications are resilient to failures.- AWS OFFICIALUpdated 3 years ago0 votes110 viewsThis selection includes content and solutions supporting FSI related compliance and requirements covering security, immutable storage, and general guidance.
- AWS OFFICIALUpdated 3 years ago0 votes299 viewsAs a best practice, AWS recommends that you use AWS Identity and Access Management (IAM) roles instead of IAM users with long-term credentials such as access keys.
- AWS OFFICIALUpdated 3 years ago0 votes66 viewsAccelerate your business transformation goals with a managed service that combines compute, network and storage capabilities in a fully supported, ready-to-run service from VMware and AWS.
- AWS OFFICIALUpdated 3 years ago0 votes8.2K viewsAre you getting 403 Access Denied errors with your Amazon Simple Storage Service (Amazon S3) operations? Review this list of handpicked resources to identify the root cause and troubleshooting instruc...
Riku_Kobayashi
EXPERTGary Mclean
EXPERTsecondabhi_aws
EXPERTOleksii Bebych
EXPERTKidd Ip
EXPERTGreg
EXPERTFlorian Turnwald
EXPERTOsvaldo Marte
EXPERTIsaac Behrens
EXPERTSedat SALMAN
EXPERTAdeleke Adebowale .J.
EXPERTTushar Jagdale
EXPERTMatt Barbieri
EXPERTAWS-User-alantam
EXPERTIndranil Banerjee AWS
EXPERTTakahito Iwasa
EXPERTMassimilianoAWS
EXPERTGK
EXPERT
