AUTO-UPDATED

Amazon Neptune now supports tag-based access control for IAM

Amazon Neptune now supports tag-based access control, allowing administrators to manage database cluster permissions dynamically using AWS resource tags and IAM principal attributes instead of individual resource identifiers.

Key Points

  • Amazon Neptune now enables tag-based access control (TBAC) for IAM policies and Service Control Policies (SCPs).
  • Users can restrict database operations by matching IAM principal tags to specific Neptune cluster tags.
  • The feature supports federated identity workflows using SAML or OIDC session tags from external providers.
  • Implementation requires Neptune engine version 1.2.0.0 or later with IAM authentication enabled.
  • The update is available in all AWS regions where Amazon Neptune is currently supported.

Why it Matters

This update simplifies security management for organizations operating large-scale database environments by removing the need to manually update policies for every individual cluster. It enhances security posture by enforcing automated, attribute-based access boundaries that prevent unauthorized lateral movement between projects.
Amazon.com Published by aws@amazon.com
Read original