Security, Identity, & Compliance
Recent questions
see all- I'm federating a GCP service account into AWS via Workload Identity Federation (no static AWS access keys) using `sts:AssumeRoleWithWebIdentity`, and every attempt fails with: An error occu...
- QUESTIONS 1. Is the ~10 second wait expected? The documentation states a 2 second timeout. 2. Is resolving with an empty value (instead of throwing) an intended outcome? If so, under what conditi...
- I'm getting SubscriptionRequiredException ("The AWS Access Key Id needs a subscription for the service") when calling Amazon Textract's DetectDocumentText API, and I've ruled out the usual causes: - ...
- I am implementing custom logic in Lambda to detect malicious clients. I want to identify and block malicious scripts/bots. WAF rules seem to a good fit. Would using online databases help? Should I jus...
- I'm new to Amazon SES and currently trying to understand how the Production Access review works in practice. The official AWS documentation explains the process, but it's still pretty unclear what AWS...
- I would like to raise a concern about the apparent ease with which newly created AWS accounts are being approved for SES production access. A lot of people are mass-registering accounts and obtaining...
- Hi there, I'm trying to understand why Amazon SES production access seems to be much easier for some customers than for others. Some users create a new AWS account, properly verify their domain, conf...
- Hi everyone I've been thinking about how automatic production access approvals in Amazon SES can affect the overall email environment. Automatic approvals can be convenient, but they also mean that ...
- I use Amazon SES for legitimate business communication, and reliable delivery is important to my daily work. Until recently, I did not pay much attention to how other accounts received Production Acce...
- I previously posted about this concern, but the post was removed. I do not know the exact reason, so I am raising it again more carefully and intentionally leaving out names, links, seller details, an...
- Lately I've been seeing many discussions about two topics related to Amazon SES: automatic Production Access approvals and concerns about shared IP reputation and deliverability. Seeing these conversa...
- Hello, I received an email from AWS confirming that my request for EC2 access in the US East (N. Virginia) region has been validated. However, I still cannot launch any EC2 instance, including t3.mi...
- Anytime we save our WAF Web ACL's rules we're getting this error: "ValidationException 1 validation error detected: Value '{}' at 'associationConfig.challengeJavascriptSdkInjection' failed to satisfy ...
- Hi, I would like to draw your attention to the critical situation with Amazon SES. Recently, spammers have discovered an easy way to bypass checks and massively obtain production access in several reg...
- Last month I had a DevOps Agent Enterprise Support Credit $5709 in my Organization account and it was expired on 31st July 2026 and we did not use it anymore and not previouly use the service. Now I...
- I manage multiple Amazon SES accounts for different businesses and rely on shared IP pools for a significant portion of my email traffic. Over the past months, I have noticed a decline in inbox place...
- Hi AWS Community & Moderators, I am facing an issue with my AWS account verification. Every time I try to submit my details, I get a red error message. I created a support case for this, but it has...
- We have a Windows Forms desktop application in which users authenticate through an Amazon Cognito user pool. After signing in, the application must access specific Amazon S3 buckets or prefixes based ...
Recent Knowledge Center content
see allRecent articles
see allVamsi KrishnaEXPERT
published 12 hours ago0 votes51 views
This article guides AWS Enterprise Support customers in education and government on how to strengthen their security posture using four AWS capabilities — Security Agent (prevent), Security Hub Unifie...Chirag_RSUPPORT ENGINEER
published 15 hours ago0 votes36 views
This article will help customers using AWS Devops Agent with resources in Azure to integrate the Azure Devops/Cloud environment to have a streamlined tool.Manish MishraEXPERT
published 3 days ago0 votes96 views
You DM the bot in Teams (or @mention it in a channel). DevOps Agent responds directly in the conversation. If it kicks off an investigation, the results come back in the same thread when it's done. Fo...- AWS OFFICIALUpdated 5 days ago0 votes68 viewsIf you build or operate a service on AWS where users can share, generate, process, distribute, or store imagery, you might encounter non-consensual intimate imagery (NCII) or other forms of image-base...
Lucky IkaniSUPPORT ENGINEER
published 8 days ago2 votes114 views
I created a cross-account AWS Transit Gateway VPC attachment and it was accepted, but the attachment transitioned to a "failed" state instead of "available."Manish MishraEXPERT
published 8 days ago0 votes158 views
Chat and Kick-off DevOps agent investigation with context from Slack Channel. Allows multiple engineers to collaborate with DevOps Agent on the same incident thread simultaneouslyNate LeeSUPPORT ENGINEER
published 8 days ago2 votes184 views
Step-by-step guide to enable VPN BGP Logging on AWS Site-to-Site VPN, verify logs in CloudWatch, set up AWS DevOps Agent, and use natural language to analyze BGP session issues automatically.NiharSUPPORT ENGINEER
published 13 days ago0 votes98 views
Customers signing in to Kiro via app.kiro.dev using IAM Identity Center are unexpectedly redirected to aws.amazon.com/q/developer/. This occurs when the Kiro Sign-In application in IAM Identity Center...- AWS OFFICIALUpdated 14 days ago0 votes77 viewsThis article explains the domain name dispute resolution process and the options that are available to you for domain names that you register through Amazon Route 53.
Usama AshrafEXPERT
published 14 days ago6 votes135 views
Cannot Delete Permission Set: Removing Orphaned ApplicationProfile Associations Before Permission Set DeletionManish MishraEXPERT
published 16 days ago0 votes106 views
AWS DevOps Agent can investigate incidents autonomously, but it doesn't have a native Jira integration. This article shows how to connect the two bidirectionallyVinuthna KorinniEXPERT
published 19 days ago0 votes194 views
A step-by-step guide for separating production workloads from your AWS management account by migrating to a new organizationWAZEXPERT
published 19 days ago0 votes111 views
Part 3 of a three-part series mapping the OWASP Top 10 for Agentic Applications 2026 to AWS security controls. This final part covers the system's dynamics once agents persist state and act autonomous...WAZEXPERT
published 19 days ago0 votes114 views
Part 2 of a three-part series mapping the OWASP Top 10 for Agentic Applications 2026 to AWS security controls. This part covers what the agent runs at runtime: ASI02 (tool misuse and abuse), ASI04 (ag...Rodrigo ReyesSUPPORT ENGINEER
published 20 days ago0 votes137 views
On June 15, 2026, AWS WAF added AI traffic monetization, a Bot Control capability that lets content and API providers charge AI bots and agents for access to protected resources directly at the edge. ...KartikEXPERT
published 20 days ago0 votes120 views
AWS DevOps Agent does not currently list Amazon OpenSearch Service as a built-in telemetry connector. This article compares six supported integration patterns—CloudWatch Logs, MCP, remote A2A, webhook...KartikEXPERT
published 21 days ago0 votes121 views
Many operations teams manage incidents in Jira, while AWS DevOps Agent investigates issues using telemetry, code, and deployment data. This article presents a bridge pattern that creates a Jira issue,...Fernandes Costa, JorgeEXPERT
published 21 days ago1 votes135 views
Context: Live video workflows on AWS Media Services (MediaConnect, MediaLive, MediaPackage) require rapid incident response — viewer impact is measured in seconds. Workflow monitor deploys best-practi...
Recent selections
see allAWS OfficialMODERATOR
published a month ago0 votes188 views
This spotlight on AWS Certificate Manager (ACM) equips you with the skills and troubleshooting tips to get the most out of a powerful service.- AWS OFFICIALUpdated 4 months ago1 votes254 viewsAWS Official content is created by a team of technical experts, professional writers, and editors within AWS. They work together to make sure that the information is clear, comprehensive, and aligned ...
AWS OfficialMODERATOR
published 4 months ago0 votes238 views
This spotlight on AWS IAM equips you with skills and troubleshooting best practices to secure and manage access to your AWS resources effectively.AWS OfficialMODERATOR
published 10 months ago1 votes388 views
This spotlight on Amazon Cognito equips you with the skills and troubleshooting best practices to get the most out of this cost effective service.AWS OfficialEXPERT
published 2 years ago0 votes1K views
This spotlight on IAM equips you with the skills and troubleshooting tips to get the most out of a powerful service.- AWS OFFICIALUpdated 4 days ago14 votes37.3K viewsThe AWS Trust & Safety Center provides curated knowledge of AWS resources that can assist you in your cloud journey.
Osvaldo MarteEXPERT
published 2 years ago2 votes18.7K views
This selection focuses on the essential AWS networking services, providing a comprehensive overview of tools and technologies available to build and manage secure, scalable, and high-performing networ...Antonio LagrotteriaEXPERT
published 2 years ago4 votes28.4K views
A selection of architectural patterns and tips to leverage secure cross-account APIs, showing ingress, egress and inspection reference architecturesJonathan_DEXPERT
published 3 years ago4 votes12.4K views
Do you have critical workloads running in AWS? Review these handpicked resources to find ways to ensure your applications are resilient to failures.- AWS OFFICIALUpdated 3 years ago0 votes110 viewsThis selection includes content and solutions supporting FSI related compliance and requirements covering security, immutable storage, and general guidance.
- AWS OFFICIALUpdated 3 years ago0 votes292 viewsAs a best practice, AWS recommends that you use AWS Identity and Access Management (IAM) roles instead of IAM users with long-term credentials such as access keys.
- AWS OFFICIALUpdated 3 years ago0 votes65 viewsAccelerate your business transformation goals with a managed service that combines compute, network and storage capabilities in a fully supported, ready-to-run service from VMware and AWS.
- AWS OFFICIALUpdated 3 years ago0 votes8.2K viewsAre you getting 403 Access Denied errors with your Amazon Simple Storage Service (Amazon S3) operations? Review this list of handpicked resources to identify the root cause and troubleshooting instruc...
Riku_Kobayashi
EXPERTGary Mclean
EXPERTsecondabhi_aws
EXPERTOleksii Bebych
EXPERTKidd Ip
EXPERTGreg
EXPERTFlorian Turnwald
EXPERTOsvaldo Marte
EXPERTBehrens, Isaac
EXPERTSedat SALMAN
EXPERTAdeleke Adebowale .J.
EXPERTTushar Jagdale
EXPERTMatt Barbieri
EXPERTAWS-User-alantam
EXPERTIndranil Banerjee AWS
EXPERTTakahito Iwasa
EXPERTMassimilianoAWS
EXPERTGK
EXPERT
