Introducing attribute-based access control for Amazon S3 general purpose buckets
AWS News Blog
This article introduces attribute-based access control (ABAC) for Amazon S3 general purpose buckets, enabling tag-based permission management at scale.
- ABAC uses tags on S3 buckets to automatically grant or deny access based on matching IAM policy conditions
- Simplifies permissions management by using tags like environment:development instead of individual bucket names
- Enable ABAC per bucket via S3 console, AWS CLI PutBucketAbac API, or CloudFormation
- Create IAM policies with StringEquals conditions matching bucket tags to control access
- Enforce tagging requirements during bucket creation using SCPs or IAM policies
- Same tags can serve as cost allocation tags for billing and cost analysis
- Available now at no additional cost across console, API, SDKs, CLI, and CloudFormation
- Works with S3 directory buckets, access points, and S3 Tables
ABAC reduces administrative overhead for large organizations managing multi-tenant S3 environments by automating access control through consistent tagging strategies.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Nov 21
2025
2025
Amazon S3 now supports attribute-based access control
Aug 1
2025
2025
Amazon S3 Access Points now support tags for Attribute-Based Access Control
Nov 18
2024
2024
Amazon DynamoDB announces general availability of attribute-based access control
Sep 3
2024
2024
Amazon DynamoDB announces support for Attribute-Based Access Control
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.