logo

From Brittle to Scalable: AWS Boosts VPC Perimeter Security with New IAM Keys

ID: cee3e9b6-3a5f-53b6-a668-b86064c3a69a

STIX ID: report--cee3e9b6-3a5f-53b6-a668-b86064c3a69a

Feed Name: Tenable Blog

Date Published: 2025-12-01

Date Updated: 2026-05-01

Author: Lior Zatlavi

...
...

AWS introduced three IAM condition keys for VPC endpoints (aws:VpceAccount, aws:VpceOrgID, aws:VpceOrgPaths) that let teams enforce scalable, identity-centric perimeters by restricting access to resources (e.g., S3, DynamoDB) based on the owning account, organization, or OU. The article explains example policy constructs and the use of resource control policies to apply org-wide guardrails, and highlights caveats—limited initial service support and the need to add exceptions for AWS-managed services—along with guidance to test thoroughly before production rollout.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.