Security, Identity, & Compliance
Recent questions
see all- I am unable to create Kiro subscriptions for any users in my AWS Organization. This issue has persisted for over 72 hours since organization creation, and all configuration requirements have been veri...
- Hello, We are investigating a change in behavior in AWS IoT JITP (Just-In-Time Provisioning). For several years, our JITP template worked correctly when a device was reprovisioned with a new certific...
- Submitted a production access request 2026-07-01 for a low-volume transactional sender (personalized daily email digest, double opt-in only). case ID (**************) Answered AWS's follow-up quest...
- I submitted a request to move my Amazon SES account out of the sandbox over a week ago and have not received any response — no approval, no rejection, and no follow-up questions. I also replied to th...
- Hi , I am going through "AWS Cloud Quest: Generative AI Practitioner" course and current in "Create an AI Smart Assistant" chapter, the lab session provided is not allowing me to create an AI Agent ...
- Hi all, I get this error when running the LZA Pipeline. The route table ( tgw-rtb-0fcce89595db4b140|0.0.0.0/0) was manually deleted. AWSAccelerator-NetworkAssociationsStack-818616066462-eu-west-1 fa...
- I can not long into root user account after resetting password and authenticator. Please help
- As per this announcement - [AWS Network Firewall updates default drop action for improved connection reliability](https://aws.amazon.com/about-aws/whats-new/2026/06/aws-network-firewall-updates-defaul...
- AWS Community, I am very new to working with AWS so forgive my ignorance. I am working on an app that uses Guard Duty (GD) to scan S3 for malware. In order to test some features for the app, I need to...
- I have one AWS account and there are multiple AWS resources including VM and all. I want to adopt zero trust policy. there is a system admin I knew, Now to access a VM for a particular troubleshooting...
- Hello, I'm trying to assign a Kiro Pro subscription to an IAM Identity Center user from the AWS Console, but every attempt fails with the following error: `Failed to create Kiro subscription for 1 u...
- Hi all, I'm using the AWS AI Security Agent to perform automated DAST scans on our enterprise web applications. However, i'm facing a critical blocker: my target applications enforce complex Multi-Fa...
- Hi AWS team, I have an open support case requesting Amazon SES production access (moving out of the sandbox) for a domain in the ap-south-1 region. Case ID: ******* Timeline: - The request has been...
- Hi, I’m testing IAM Access Analyzer Internal Access with an S3 bucket in one account and IAM roles in another account within the same AWS Organization. I attached an SCP to the OU that denies: s3:D...
- **Issue:** Amazon Q Developer Pro subscription creation consistently failing despite correct configuration and active startup program credits. **Error Message:** "Failed to create Kiro subscription ...
- Hello, I made a Pay-as-you-go CloudFront distribution with a Custom Origin outside AWS, to a website that runs at a hosting provider Bluehost: https://pfa.mihaiadam.com . I used the valid SSL certi...
- Hi Community, I'm looking for a way to automate the lifecycle of AWS IAM Access Keys and Secret Keys. **Current state:** * I've already implemented a POC using **IAM Roles Anywhere**. While it work...
- AWS DevOps Agent offers built-in native integrations for observability platforms like Datadog, New Relic, Dynatrace, Splunk, and Grafana. However, there is no built-in integration for Observe at this ...
Recent Knowledge Center content
see allRecent articles
see allKartikEXPERT
published a day ago0 votes55 views
AWS DevOps Agent's release readiness review is native to GitHub and GitLab, but not to BitBucket Cloud. This article covers a bridge pattern (Amazon Bedrock AgentCore Gateway, Amazon Cognito, and a si...- AWS OFFICIALUpdated 2 days ago0 votes455 viewsLearn how AWS DevOps Agent investigates your operational issues autonomously in the AWS Support Center Console, delivering root cause analysis and reducing resolution time.
LokeshEXPERT
published 2 days ago1 votes23 views
Enterprise organizations running 1000+ AWS accounts need AWS DevOps Agent to trace root causes across account boundaries — from workload accounts through shared networking and centralized logging. Thi...- AWS OFFICIALUpdated 3 days ago0 votes77 viewsYou can use Kiro CLI with the AWS Model Context Protocol (MCP) Server to query AWS DevOps Agent investigations and review root cause findings. These tools can also help you provide additional context ...
David VEXPERT
published 3 days ago4 votes161 views
AWS doesn't offer native per-user spend caps for Amazon Bedrock. This guide provides a production-ready architecture for enforcing per-user monthly budget limits on Bedrock for Identity Center (SSO) u...- AWS OFFICIALUpdated 2 days ago0 votes118 viewsLearn how to route AWS Incident Detection and Response alarms to AWS DevOps Agent for instant, autonomous investigation when an alarm activates.
Rob_HEXPERT
published 5 days ago0 votes118 views
When enforcing zero data retention on Amazon Bedrock with an SCP, there's an important prerequisite: new accounts default to inherit (not none). The SCP prevents changing the mode, but it doesn't set ...Liam_MSUPPORT ENGINEER
published 10 days ago0 votes37 views
Amazon GameLift Servers now offers DDoS Protection client SDKs for C# and Unity, expanding support beyond C++ and Unreal Engine to help more game developers protect multiplayer games against denial-of...KinjanEXPERT
published 10 days ago0 votes49 views
Account closure does not automatically clean up AWS Security Incident Response (SIR). This article explains the SIR-specific steps to take before closing accounts: removing them from OU-based scope, d...Ram AchantaEXPERT
published 11 days ago2 votes94 views
Organizations scaling AWS workloads across EC2, EMR, containers, and Lambda face growing vulnerability counts that overwhelm application teams. Challenges include EMR on EC2 vulnerability multiplicati...Akhilesh-Sr TAMEXPERT
published 11 days ago0 votes41 views
Enterprises upgrading their AWS Lake Formation cross-account sharing to Version 5 may get blocked from granting data access across accounts breaking cross-account data lake workflows. This article pro...- AWS OFFICIALUpdated 11 days ago1 votes186 viewsThis article shows how to troubleshoot faster with four AWS AI-powered tools, including Amazon Q Developer, Kiro CLI, AWS DevOps Agent, and AI-enhanced troubleshooting in the AWS Support Center.
published 13 days ago0 votes62 views
Parts 1–3 covered runtime failures. This one tackles the opposite: change-time failures that pass every pipeline check yet still reach production — because staging drifts from production and tests jud...published 13 days ago0 votes62 views
To show builders how to compose a single scheduled custom SRE agent — using AWS DevOps Agent's own custom-agents capability (June 2026) — that runs a daily Start-of-Day Readiness SOP and answers one b...NiharSUPPORT ENGINEER
published 17 days ago0 votes156 views
This article explains how to enable and configure the AWS Kiro Enterprise subscription for organizations that use a cross-account STS AssumeRole model, where IAM users log in to a central identity acc...Kumar ShubhamEXPERT
published 19 days ago0 votes106 views
AWS DevOps Agent's Topology, the map of resources and relationships it consults during incident investigations, is built partly from resource tags. Inconsistent or missing tags slow the agent down. Th...Kumar ShubhamEXPERT
published 19 days ago0 votes227 views
AWS DevOps Agent now offers headless access via the Model Context Protocol (MCP), letting developers invoke production observability and root-cause investigations directly from Kiro, Claude Code, Curs...published 20 days ago0 votes75 views
Score your own support cases by addressability to build an evidence-based AI ops agent roadmap
Recent selections
see all- AWS OFFICIALUpdated 3 months ago1 votes219 viewsAWS Official content is created by a team of technical experts, professional writers, and editors within AWS. They work together to make sure that the information is clear, comprehensive, and aligned ...
AWS OfficialMODERATOR
published 3 months ago0 votes195 views
This spotlight on AWS IAM equips you with skills and troubleshooting best practices to secure and manage access to your AWS resources effectively.AWS OfficialMODERATOR
published 9 months ago1 votes345 views
This spotlight on Amazon Cognito equips you with the skills and troubleshooting best practices to get the most out of this cost effective service.AWS OfficialEXPERT
published 2 years ago0 votes1K views
This spotlight on IAM equips you with the skills and troubleshooting tips to get the most out of a powerful service.- AWS OFFICIALUpdated 2 days ago11 votes34.3K viewsThe AWS Trust & Safety Center provides curated knowledge of AWS resources that can assist you in your cloud journey.
Osvaldo MarteEXPERT
published 2 years ago2 votes18.7K views
This selection focuses on the essential AWS networking services, providing a comprehensive overview of tools and technologies available to build and manage secure, scalable, and high-performing networ...Antonio LagrotteriaEXPERT
published 2 years ago4 votes28.3K views
A selection of architectural patterns and tips to leverage secure cross-account APIs, showing ingress, egress and inspection reference architecturesJonathan_DEXPERT
published 3 years ago4 votes12.4K views
Do you have critical workloads running in AWS? Review these handpicked resources to find ways to ensure your applications are resilient to failures.- AWS OFFICIALUpdated 3 years ago0 votes105 viewsThis selection includes content and solutions supporting FSI related compliance and requirements covering security, immutable storage, and general guidance.
- AWS OFFICIALUpdated 3 years ago0 votes273 viewsAs a best practice, AWS recommends that you use AWS Identity and Access Management (IAM) roles instead of IAM users with long-term credentials such as access keys.
- AWS OFFICIALUpdated 3 years ago0 votes61 viewsAccelerate your business transformation goals with a managed service that combines compute, network and storage capabilities in a fully supported, ready-to-run service from VMware and AWS.
- AWS OFFICIALUpdated 3 years ago0 votes8.2K viewsAre you getting 403 Access Denied errors with your Amazon Simple Storage Service (Amazon S3) operations? Review this list of handpicked resources to identify the root cause and troubleshooting instruc...
Riku_Kobayashi
EXPERTGary Mclean
EXPERTsecondabhi_aws
EXPERTOleksii Bebych
EXPERTGreg
EXPERTKidd Ip
EXPERTOsvaldo Marte
EXPERTBehrens, Isaac
EXPERTSedat SALMAN
EXPERTAdeleke Adebowale .J.
EXPERTFlorian Turnwald
EXPERTTushar Jagdale
EXPERTMatt Barbieri
EXPERTAWS-User-alantam
EXPERTIndranil Banerjee AWS
EXPERTTakahito Iwasa
EXPERTMassimilianoAWS
EXPERTGK
EXPERT
