Security, Identity, & Compliance
Recent questions
see all- Hi, We are facing issues with federating in to AWS using our OIDC isser IDP: iamcredentials.apis-tpczero.goog Things we have done till now: 1) Created a identity provider in AWS: \ provider: iamcre...
- Hello, My Amazon SES production-access workflow is stuck because it remains linked to a closed support case. Region: us-east-2 The SES console instructs me to provide additional information through...
- Hi there I'm not trying to criticize the idea of reviewing SES accounts. The concern is how some decisions are being made. If an account with a properly configured domain and a clear use case is rej...
- There is currently a stark inconsistency in how production access is granted across accounts. Certain accounts receive instant automated approvals, while compliant senders who strictly follow SES guid...
- I considered Amazon SES because AWS is associated with secure infrastructure, reliable services, and careful controls. That reputation is one of the main reasons businesses trust AWS with important em...
- I've noticed that Amazon SES can give very different results for production access requests. Some accounts are approved automatically, while others with properly configured domains and clear use cases...
- I am trying to understand if it is possible to get a true single sign-on user experience when using an IAM identity center instance (service provider) with Microsoft Entra ID as the external identity ...
- Amazon Inspector Code Security (GitHub integration, ap-northeast-1) flagged 241 "CWE-89 - SQL Injection" findings in a CodeIgniter 4 PHP application. On manual review, every sampled instance uses Code...
- I don't understand why Amazon SES can automatically approve some accounts while new customers with properly configured domains are sent to manual review or rejected. If an account is approved automati...
- Hi everyone, I’ve been reading some discussions on the forum about automatic approvals for production access, and I’d like to understand how this works. I’ve tried several times to get production acc...
- Hello AWS Team & Community Managers, I am requesting assistance to route an open SES Support ticket to the Trust & Safety review team. Our application for SES Production Access was submitted on July...
- I chose Amazon SES because AWS has a strong reputation for stable infrastructure and reliable business services. A company can accept a strict production access process when it believes the same stand...
- I am using Forgejo 15.0.6 LTS with an AWS IAM OIDC provider configured for: ```text Issuer: https://git.sakthisanthosh.in/api/actions Audience: sts.amazonaws.com Subject: repo:ssanumand/lad-forgejo-a...
- I'm federating a GCP service account into AWS via Workload Identity Federation (no static AWS access keys) using `sts:AssumeRoleWithWebIdentity`, and every attempt fails with: An error occu...
- QUESTIONS 1. Is the ~10 second wait expected? The documentation states a 2 second timeout. 2. Is resolving with an empty value (instead of throwing) an intended outcome? If so, under what conditi...
- I'm getting SubscriptionRequiredException ("The AWS Access Key Id needs a subscription for the service") when calling Amazon Textract's DetectDocumentText API, and I've ruled out the usual causes: - ...
- I am implementing custom logic in Lambda to detect malicious clients. I want to identify and block malicious scripts/bots. WAF rules seem to a good fit. Would using online databases help? Should I jus...
- Hello, I received an email from AWS confirming that my request for EC2 access in the US East (N. Virginia) region has been validated. However, I still cannot launch any EC2 instance, including t3.mi...
Recent Knowledge Center content
see allRecent articles
see all- AWS OFFICIALUpdated a day ago0 votes64 viewsThis article shows you how to use Amazon CloudWatch and AWS DevOps Agent to build an automated cost spike detection pipeline for Amazon Bedrock.
Jiwon JungEXPERT
published 5 days ago0 votes58 views
A member account needs to be migrated to another AWS Organization. This account consumes resources shared by another account through AWS RAM. Because organization-scoped resource shares are automatica...Lucky IkaniSUPPORT ENGINEER
published 5 days ago1 votes85 views
I want to use multiple AWS Client VPN endpoints in different AWS accounts with the same Microsoft Entra ID (Azure AD) tenant for SAML authentication. When I create a second enterprise application in E...SapirEXPERT
published 6 days ago2 votes107 views
A step-by-step guide to connecting AWS DevOps Agent to a self-managed, privately hosted GitLab using a Private Connection over Amazon VPC Lattice - so you can have the agent investigate your repositor...Vamsi KrishnaEXPERT
published 7 days ago0 votes103 views
This article guides AWS Enterprise Support customers in education and government on how to strengthen their security posture using four AWS capabilities — Security Agent (prevent), Security Hub Unifie...Chirag_REXPERT
published 7 days ago0 votes95 views
This article will help customers using AWS Devops Agent with resources in Azure to integrate the Azure Devops/Cloud environment to have a streamlined tool.Manish MishraEXPERT
published 10 days ago0 votes151 views
You DM the bot in Teams (or @mention it in a channel). DevOps Agent responds directly in the conversation. If it kicks off an investigation, the results come back in the same thread when it's done. Fo...- AWS OFFICIALUpdated 11 days ago0 votes102 viewsIf you build or operate a service on AWS where users can share, generate, process, distribute, or store imagery, you might encounter non-consensual intimate imagery (NCII) or other forms of image-base...
Lucky IkaniSUPPORT ENGINEER
published 14 days ago3 votes168 views
I created a cross-account AWS Transit Gateway VPC attachment and it was accepted, but the attachment transitioned to a "failed" state instead of "available."Manish MishraEXPERT
published 15 days ago0 votes197 views
Chat and Kick-off DevOps agent investigation with context from Slack Channel. Allows multiple engineers to collaborate with DevOps Agent on the same incident thread simultaneouslyNate LeeSUPPORT ENGINEER
published 15 days ago2 votes212 views
Step-by-step guide to enable VPN BGP Logging on AWS Site-to-Site VPN, verify logs in CloudWatch, set up AWS DevOps Agent, and use natural language to analyze BGP session issues automatically.NiharSUPPORT ENGINEER
published 19 days ago0 votes114 views
Customers signing in to Kiro via app.kiro.dev using IAM Identity Center are unexpectedly redirected to aws.amazon.com/q/developer/. This occurs when the Kiro Sign-In application in IAM Identity Center...- AWS OFFICIALUpdated 20 days ago0 votes101 viewsThis article explains the domain name dispute resolution process and the options that are available to you for domain names that you register through Amazon Route 53.
Usama AshrafEXPERT
published 21 days ago6 votes144 views
Cannot Delete Permission Set: Removing Orphaned ApplicationProfile Associations Before Permission Set DeletionManish MishraEXPERT
published 22 days ago0 votes136 views
AWS DevOps Agent can investigate incidents autonomously, but it doesn't have a native Jira integration. This article shows how to connect the two bidirectionallyVinuthna KorinniEXPERT
published 25 days ago0 votes208 views
A step-by-step guide for separating production workloads from your AWS management account by migrating to a new organizationWAZEXPERT
published a month ago0 votes127 views
Part 3 of a three-part series mapping the OWASP Top 10 for Agentic Applications 2026 to AWS security controls. This final part covers the system's dynamics once agents persist state and act autonomous...WAZEXPERT
published a month ago0 votes125 views
Part 2 of a three-part series mapping the OWASP Top 10 for Agentic Applications 2026 to AWS security controls. This part covers what the agent runs at runtime: ASI02 (tool misuse and abuse), ASI04 (ag...
Recent selections
see allAWS OfficialMODERATOR
published a month ago0 votes212 views
This spotlight on AWS Certificate Manager (ACM) equips you with the skills and troubleshooting tips to get the most out of a powerful service.- AWS OFFICIALUpdated 4 months ago1 votes285 viewsAWS Official content is created by a team of technical experts, professional writers, and editors within AWS. They work together to make sure that the information is clear, comprehensive, and aligned ...
AWS OfficialMODERATOR
published 4 months ago0 votes241 views
This spotlight on AWS IAM equips you with skills and troubleshooting best practices to secure and manage access to your AWS resources effectively.AWS OfficialMODERATOR
published a year ago1 votes408 views
This spotlight on Amazon Cognito equips you with the skills and troubleshooting best practices to get the most out of this cost effective service.AWS OfficialEXPERT
published 2 years ago0 votes1K views
This spotlight on IAM equips you with the skills and troubleshooting tips to get the most out of a powerful service.- AWS OFFICIALUpdated 11 days ago14 votes38.1K viewsThe AWS Trust & Safety Center provides curated knowledge of AWS resources that can assist you in your cloud journey.
Osvaldo MarteEXPERT
published 2 years ago2 votes18.7K views
This selection focuses on the essential AWS networking services, providing a comprehensive overview of tools and technologies available to build and manage secure, scalable, and high-performing networ...Antonio LagrotteriaEXPERT
published 2 years ago4 votes28.4K views
A selection of architectural patterns and tips to leverage secure cross-account APIs, showing ingress, egress and inspection reference architecturesJonathan_DEXPERT
published 3 years ago4 votes12.5K views
Do you have critical workloads running in AWS? Review these handpicked resources to find ways to ensure your applications are resilient to failures.- AWS OFFICIALUpdated 3 years ago0 votes111 viewsThis selection includes content and solutions supporting FSI related compliance and requirements covering security, immutable storage, and general guidance.
- AWS OFFICIALUpdated 3 years ago0 votes299 viewsAs a best practice, AWS recommends that you use AWS Identity and Access Management (IAM) roles instead of IAM users with long-term credentials such as access keys.
- AWS OFFICIALUpdated 3 years ago0 votes66 viewsAccelerate your business transformation goals with a managed service that combines compute, network and storage capabilities in a fully supported, ready-to-run service from VMware and AWS.
- AWS OFFICIALUpdated 3 years ago0 votes8.2K viewsAre you getting 403 Access Denied errors with your Amazon Simple Storage Service (Amazon S3) operations? Review this list of handpicked resources to identify the root cause and troubleshooting instruc...
Riku_Kobayashi
EXPERTGary Mclean
EXPERTsecondabhi_aws
EXPERTOleksii Bebych
EXPERTKidd Ip
EXPERTGreg
EXPERTFlorian Turnwald
EXPERTOsvaldo Marte
EXPERTIsaac Behrens
EXPERTSedat SALMAN
EXPERTAdeleke Adebowale .J.
EXPERTTushar Jagdale
EXPERTMatt Barbieri
EXPERTAWS-User-alantam
EXPERTIndranil Banerjee AWS
EXPERTTakahito Iwasa
EXPERTMassimilianoAWS
EXPERTGK
EXPERT
