Amazon SageMaker adds permissions boundaries for SCP compliance
Share
Services
Amazon SageMaker Unified Studio now supports custom IAM permissions boundaries, so organizations that enforce Service Control Policies (SCPs) requiring permissions boundaries on all IAM roles can adopt SageMaker Unified Studio without modifying their security posture.
When a user creates a project, SageMaker Unified Studio provisions three IAM roles: a project user role, an Amazon Bedrock service role, and a Bedrock Lambda execution role. With this launch, administrators can specify a permissions boundary in the Tooling blueprint configuration, and all three roles are created with that permissions boundary attached. This satisfies SCP requirements at creation time, and project provisioning succeeds without administrator intervention. The permissions boundary also limits what the provisioned roles can do, so administrators retain control over project-level permissions even as new projects are created. Because the permissions boundary is set at the blueprint level, it applies to every new project automatically.
This feature is available in all [AWS Regions where Amazon SageMaker Unified Studio](https://docs.aws.amazon.com/sagemaker-unified-studio/latest/adminguide/supported-regions.html) is available. To learn more, visit the [Manage Tooling blueprint parameters](https://docs.aws.amazon.com/sagemaker-unified-studio/latest/adminguide/manage-tooling-blueprint.html) documentation.
What else is happening at Amazon Web Services?
Amazon EC2 M8azn instances are now available in Europe (Ireland) Region
about 10 hours ago
Services
Share
Amazon EC2 M8i and M8i-flex instances are now available in Asia Pacific (New Zealand) Region
about 10 hours ago
Services
Share
Amazon Bedrock AgentCore Identity now allows you to bring your own secrets with AWS Secrets Manager
about 10 hours ago
Services
Share
AWS Direct Connect now supports VIF Rate Limiters to help prevent network congestion
about 11 hours ago
Services
Share
Amazon Bedrock adds Amazon CloudWatch metrics for OpenAI- and Anthropic-compatible APIs
about 12 hours ago
Services
Share
GPT-5.5, GPT-5.4, and Codex from OpenAI are now generally available on Amazon Bedrock
about 13 hours ago
Services
Share