Amazon SageMaker Unified Studio now supports custom IAM permissions boundaries, enabling organizations with Service Control Policies (SCPs) that require permissions boundaries on all IAM roles to adopt the platform without changing their security posture. When a project is created, SageMaker provisions three IAM roles and automatically attaches the specified permissions boundary from the Tooling blueprint configuration. This satisfies SCP requirements at creation time, eliminates the need for administrator intervention, and applies consistently to every new project. The feature is available in all AWS regions where SageMaker Unified Studio is supported.
70 Impressions