Home icon

IAM Roles Anywhere now enforces VPC endpoint policies for the CreateSession API

News



This article announces that IAM Roles Anywhere now enforces VPC endpoint policies for the CreateSession API, providing consistent access control across all operations.

  • VPC endpoint policies can now allow or deny the CreateSession operation
  • CreateSession must be explicitly included in VPC endpoint policy Allow statements
  • Requests without proper policy permissions will not receive temporary AWS credentials
  • CreateSession API enables external workloads to obtain AWS credentials using X.509 certificates
  • Feature available in all AWS Regions including GovCloud, European Sovereign Cloud, and China

This update closes a security gap by extending VPC endpoint policy enforcement to the CreateSession API, ensuring consistent fine-grained access control for all IAM Roles Anywhere operations.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

May 5
2026
AWS IAM now provides higher maximum quotas for roles, role trust policies, instance profiles, managed policies, and identity providers
Aug 25
2026
IAM Roles Anywhere now provides a Java plugin for the AWS SDK
Mar 4
2026
AWS simplifies IAM role creation and setup in service workflows
May 8
2026
IAM Policy Autopilot adds Java support and Terraform-aware policy generation

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.