Amazon Cognito now supports multi-Region replication, automatically synchronizing user data, credentials, and pool configurations to a secondary AWS Region. This enables uninterrupted authentication during regional failovers without forced password resets or re-authentication. Both user-facing and machine-to-machine (M2M) authentication flows are supported, including federated sign-in via social providers, SAML, and OIDC. Setup requires a customer managed KMS key replicated across regions and involves configuring multi-region OIDC endpoints. Health checks and DNS-based failover via Route 53 are recommended for traffic routing. The feature is available as a paid add-on for Essentials and Plus tier customers. Additionally, Cognito now supports customer managed KMS keys for encryption at rest, giving regulated industries more control over data protection.