Security, Identity, & Compliance
Recent questions
see all- Summary I've configured PingFederate 13.0.3 as an external SAML 2.0 identity provider for AWS IAM Identity Center. The identity source change was accepted successfully by AWS ("You successfully chang...
- Region: App Studio us-west-2, IAM Identity Center us-east-1 Note: Understanding App Studio is only available in Oregon I did switch Region to Oregon and the setup accepted my IAM group etc. Logged in...
- We remediated CVE-2026-45490 (.NET SDK Elevation of Privilege) and CVE-2026-45591 (ASP.NET Core Denial of Service) across EC2 fleets in two separate AWS accounts, both in us-east-2. In both accounts, ...
- I opted into UAE (me-central-1) on a new-ish account and can't launch compute there. - ecs:CreateCluster → ThrottlingException: "Rate exceeded" (every call, 24h+, even single calls after long idle). ...
- Here's a public-safe version for re:Post — account ID, IAM ARN, and any account-identifying details are redacted: --- **Title:** AWS FinOps Agent (Preview) — `CreateIntegration` (Slack) returns 403 ...
- How does the AWS DevOps Agent handle incident resolution across multiple AWS accounts in an AWS Organizations setup — can it correlate alarms from a shared monitoring account with resources in spoke w...
- Hi there, I am getting a SAML login failure ("Response contains invalid principal tag value... Select a role") whenever a user matches more than one Application Entitlement group - same stack or diff...
- Hello, I requested Amazon SES production access for a B2B timesheet management app and was denied by Trust & Safety after providing additional details. I'm preparing to appeal and want to know if impr...
- I'm looking for confirmation on whether my understanding is correct that AWS WAF (when attached to an Application Load Balancer) cannot enforce a rule that blocks requests whose body size exceeds a sp...
- Hi AWS community, My personal AWS account is restricted due to verification issues. I have submitted a support ticket, which has now been unassigned for over 4 weeks. Is this expected? Is there anythi...
- SUBJECT: AWS IoT Core rejects MQTT-over-WebSocket (SigV4) CONNECT with AUTHORIZATION_FAILURE despite verified-correct IAM policy, trust policy, and valid STS credentials from Cognito Identity Pool --...
- I am unable to create Kiro subscriptions for any users in my AWS Organization. This issue has persisted for over 72 hours since organization creation, and all configuration requirements have been veri...
- Hello, We are investigating a change in behavior in AWS IoT JITP (Just-In-Time Provisioning). For several years, our JITP template worked correctly when a device was reprovisioned with a new certific...
- Submitted a production access request 2026-07-01 for a low-volume transactional sender (personalized daily email digest, double opt-in only). case ID (**************) Answered AWS's follow-up quest...
- I submitted a request to move my Amazon SES account out of the sandbox over a week ago and have not received any response — no approval, no rejection, and no follow-up questions. I also replied to th...
- Hi all, I get this error when running the LZA Pipeline. The route table ( tgw-rtb-0fcce89595db4b140|0.0.0.0/0) was manually deleted. AWSAccelerator-NetworkAssociationsStack-818616066462-eu-west-1 fa...
- I can not long into root user account after resetting password and authenticator. Please help
- As per this announcement - [AWS Network Firewall updates default drop action for improved connection reliability](https://aws.amazon.com/about-aws/whats-new/2026/06/aws-network-firewall-updates-defaul...
Recent Knowledge Center content
see allRecent articles
see allSagar GandhaEXPERT
published 4 days ago0 votes47 views
AWS DevOps Agent charges per agent-second with no built-in spending cap or alert mechanism. This article walks through setting up a CloudWatch metric math alarm that sums daily consumption across all ...KartikEXPERT
published 6 days ago0 votes88 views
AWS DevOps Agent's release readiness review is native to GitHub and GitLab, but not to BitBucket Cloud. This article covers a bridge pattern (Amazon Bedrock AgentCore Gateway, Amazon Cognito, and a si...- AWS OFFICIALUpdated 7 days ago0 votes706 viewsLearn how AWS DevOps Agent investigates your operational issues autonomously in the AWS Support Center Console, delivering root cause analysis and reducing resolution time.
LokeshEXPERT
published 7 days ago1 votes50 views
Enterprise organizations running 1000+ AWS accounts need AWS DevOps Agent to trace root causes across account boundaries — from workload accounts through shared networking and centralized logging. Thi...- AWS OFFICIALUpdated 2 days ago0 votes133 viewsYou can use Kiro CLI with the AWS Model Context Protocol (MCP) Server to query AWS DevOps Agent investigations and review root cause findings. These tools can also help you provide additional context ...
David VEXPERT
published 8 days ago4 votes255 views
AWS doesn't offer native per-user spend caps for Amazon Bedrock. This guide provides a production-ready architecture for enforcing per-user monthly budget limits on Bedrock for Identity Center (SSO) u...- AWS OFFICIALUpdated 7 days ago0 votes189 viewsLearn how to route AWS Incident Detection and Response alarms to AWS DevOps Agent for instant, autonomous investigation when an alarm activates.
Rob_HEXPERT
published 9 days ago0 votes189 views
When enforcing zero data retention on Amazon Bedrock with an SCP, there's an important prerequisite: new accounts default to inherit (not none). The SCP prevents changing the mode, but it doesn't set ...KinjanEXPERT
published 15 days ago0 votes57 views
Account closure does not automatically clean up AWS Security Incident Response (SIR). This article explains the SIR-specific steps to take before closing accounts: removing them from OU-based scope, d...Ram AchantaEXPERT
published 15 days ago2 votes105 views
Organizations scaling AWS workloads across EC2, EMR, containers, and Lambda face growing vulnerability counts that overwhelm application teams. Challenges include EMR on EC2 vulnerability multiplicati...Akhilesh-Sr TAMEXPERT
published 16 days ago0 votes52 views
Enterprises upgrading their AWS Lake Formation cross-account sharing to Version 5 may get blocked from granting data access across accounts breaking cross-account data lake workflows. This article pro...- AWS OFFICIALUpdated 16 days ago1 votes221 viewsThis article shows how to troubleshoot faster with four AWS AI-powered tools, including Amazon Q Developer, Kiro CLI, AWS DevOps Agent, and AI-enhanced troubleshooting in the AWS Support Center.
published 17 days ago0 votes70 views
Parts 1–3 covered runtime failures. This one tackles the opposite: change-time failures that pass every pipeline check yet still reach production — because staging drifts from production and tests jud...published 18 days ago0 votes70 views
To show builders how to compose a single scheduled custom SRE agent — using AWS DevOps Agent's own custom-agents capability (June 2026) — that runs a daily Start-of-Day Readiness SOP and answers one b...NiharSUPPORT ENGINEER
published 21 days ago0 votes169 views
This article explains how to enable and configure the AWS Kiro Enterprise subscription for organizations that use a cross-account STS AssumeRole model, where IAM users log in to a central identity acc...Kumar ShubhamEXPERT
published 23 days ago0 votes113 views
AWS DevOps Agent's Topology, the map of resources and relationships it consults during incident investigations, is built partly from resource tags. Inconsistent or missing tags slow the agent down. Th...Kumar ShubhamEXPERT
published 23 days ago0 votes249 views
AWS DevOps Agent now offers headless access via the Model Context Protocol (MCP), letting developers invoke production observability and root-cause investigations directly from Kiro, Claude Code, Curs...published 24 days ago0 votes80 views
Score your own support cases by addressability to build an evidence-based AI ops agent roadmap
Recent selections
see allAWS OfficialMODERATOR
published 2 days ago0 votes32 views
This spotlight on AWS Certificate Manager (ACM) equips you with the skills and troubleshooting tips to get the most out of a powerful service.- AWS OFFICIALUpdated 3 months ago1 votes221 viewsAWS Official content is created by a team of technical experts, professional writers, and editors within AWS. They work together to make sure that the information is clear, comprehensive, and aligned ...
AWS OfficialMODERATOR
published 3 months ago0 votes195 views
This spotlight on AWS IAM equips you with skills and troubleshooting best practices to secure and manage access to your AWS resources effectively.AWS OfficialMODERATOR
published 9 months ago1 votes348 views
This spotlight on Amazon Cognito equips you with the skills and troubleshooting best practices to get the most out of this cost effective service.AWS OfficialEXPERT
published 2 years ago0 votes1K views
This spotlight on IAM equips you with the skills and troubleshooting tips to get the most out of a powerful service.- AWS OFFICIALUpdated 7 days ago11 votes34.7K viewsThe AWS Trust & Safety Center provides curated knowledge of AWS resources that can assist you in your cloud journey.
Osvaldo MarteEXPERT
published 2 years ago2 votes18.7K views
This selection focuses on the essential AWS networking services, providing a comprehensive overview of tools and technologies available to build and manage secure, scalable, and high-performing networ...Antonio LagrotteriaEXPERT
published 2 years ago4 votes28.3K views
A selection of architectural patterns and tips to leverage secure cross-account APIs, showing ingress, egress and inspection reference architecturesJonathan_DEXPERT
published 3 years ago4 votes12.4K views
Do you have critical workloads running in AWS? Review these handpicked resources to find ways to ensure your applications are resilient to failures.- AWS OFFICIALUpdated 3 years ago0 votes105 viewsThis selection includes content and solutions supporting FSI related compliance and requirements covering security, immutable storage, and general guidance.
- AWS OFFICIALUpdated 3 years ago0 votes273 viewsAs a best practice, AWS recommends that you use AWS Identity and Access Management (IAM) roles instead of IAM users with long-term credentials such as access keys.
- AWS OFFICIALUpdated 3 years ago0 votes63 viewsAccelerate your business transformation goals with a managed service that combines compute, network and storage capabilities in a fully supported, ready-to-run service from VMware and AWS.
- AWS OFFICIALUpdated 3 years ago0 votes8.2K viewsAre you getting 403 Access Denied errors with your Amazon Simple Storage Service (Amazon S3) operations? Review this list of handpicked resources to identify the root cause and troubleshooting instruc...
Riku_Kobayashi
EXPERTGary Mclean
EXPERTsecondabhi_aws
EXPERTOleksii Bebych
EXPERTGreg
EXPERTKidd Ip
EXPERTOsvaldo Marte
EXPERTBehrens, Isaac
EXPERTSedat SALMAN
EXPERTAdeleke Adebowale .J.
EXPERTFlorian Turnwald
EXPERTTushar Jagdale
EXPERTMatt Barbieri
EXPERTAWS-User-alantam
EXPERTIndranil Banerjee AWS
EXPERTTakahito Iwasa
EXPERTMassimilianoAWS
EXPERTGK
EXPERT
