Amazon Athena now supports user identities for data access and audit
Share
Services
[Amazon Athena](https://aws.amazon.com/athena/) now supports trusted identity propagation with [AWS IAM Identity Center](https://aws.amazon.com/iam/identity-center/) to manage and audit access to data and resources based on user identity. This new capability passes identity information between connected business intelligence and data analytics applications, providing data analysts with a seamless single sign-on experience and admins with end-to-end data access traceability. Administrators define access via [AWS Lake Formation](https://aws.amazon.com/lake-formation/) to their data sets in Glue Data Catalog based on a common set of users and groups in the customer’s chosen identity provider. Auditors can track users’ data access across their Athena query workflows.
With this launch, administrators can simply enable trusted identity propagation for Athena SQL use cases when creating a new workgroup. Data analysts can then use their corporate identities to access the Athena editor in EMR Studio where they run queries from their trusted identity propagation enabled workgroups. As the query runs, the identity of the data analyst is propagated all the way to AWS Lake Formation to authorize data access. This launch simplifies on-boarding through single-sign on, improves end-to-end security via identity-based fine-grained access control, and provides auditability for Athena query workflows.
This feature is generally available in 9 AWS Regions: US East (N. Virginia, Ohio), US West (Oregon), Asia Pacific (Singapore, Sydney), Canada (Central), and Europe (Ireland, Frankfurt and London). To get started, refer to the [documentation](https://docs.aws.amazon.com/athena/latest/ug/workgroups-identity-center.html).
What else is happening at Amazon Web Services?
Amazon AppStream 2.0 users can now save their user preferences between streaming sessions
December 13th, 2024
Services
Share
AWS Elemental MediaConnect Gateway now supports source-specific multicast
December 13th, 2024
Services
Share
Amazon EC2 instances support bandwidth configurations for VPC and EBS
December 13th, 2024
Services
Share
AWS announces new AWS Direct Connect location in Osaka, Japan
December 13th, 2024
Services
Share
Amazon DynamoDB announces support for FIPS 140-3 interface VPC and Streams endpoints
December 13th, 2024
Services
Share