Amazon Neptune now supports tag-based access control, allowing administrators to manage database cluster permissions dynamically using AWS resource tags and IAM principal attributes instead of individual resource identifiers.
Key Points
- Amazon Neptune now enables tag-based access control (TBAC) for IAM policies and Service Control Policies (SCPs).
- Users can restrict database operations by matching IAM principal tags to specific Neptune cluster tags.
- The feature supports federated identity workflows using SAML or OIDC session tags from external providers.
- Implementation requires Neptune engine version 1.2.0.0 or later with IAM authentication enabled.
- The update is available in all AWS regions where Amazon Neptune is currently supported.