Amazon S3 supports attribute-based access control (ABAC) for S3 general purpose buckets. In addition to using tags on your S3 buckets for cost allocation, you can now use them for ABAC to automatically manage permissions to your data. This helps eliminate frequent AWS Identity and Access Management (IAM) or bucket policy updates as your organization grows, simplifying how you govern access at scale.
With ABAC support, Amazon S3 automatically evaluates tag based conditions in your policies before granting access to your data. For example, create an IAM policy that references tags on your buckets, then grant users and roles access simply by adding or modifying tags to new or existing buckets. To get started, enable ABAC on your bucket using the S3 PutBucketAbac API and manage tags through the S3 TagResource and UntagResource APIs. You can also require that users add specific tags at the time of bucket creation to set consistent tagging standards across your organization.
ABAC support for S3 general purpose bucket is available in all AWS Regions at no additional cost via the AWS Management Console, S3 REST API, AWS CLI, AWS SDK, and AWS CloudFormation. To learn more about using tags for access control in S3 general purpose buckets, read our blog, or visit the S3 User Guide.
Categories: general:products/aws-govcloud-us,general:products/amazon-s3,marketing:marchitecture/storage
Source: Amazon Web Services
Latest Posts
- Amazon Connect Customer now supports embedding Cases and Customer Profiles in custom agent applications

- Collect Diagnostics change to Get Diagnostics for Outlook Mobile and Mac [MC1308855]
![Collect Diagnostics change to Get Diagnostics for Outlook Mobile and Mac [MC1308855] 3 pexels megan forbes 347998 963436](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Action required: Upgrade macOS 13 devices to maintain Teams desktop access [MC1308857]
![Action required: Upgrade macOS 13 devices to maintain Teams desktop access [MC1308857] 4 pexels pixabay 163036](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft 365 Copilot (including Copilot Chat): Admin notifications for Copilot mobile app on macOS [MC1308856]
![Microsoft 365 Copilot (including Copilot Chat): Admin notifications for Copilot mobile app on macOS [MC1308856] 5 pexels pixabay 290470](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)


![Collect Diagnostics change to Get Diagnostics for Outlook Mobile and Mac [MC1308855] 3 pexels megan forbes 347998 963436](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-megan-forbes-347998-963436-150x150.webp)
![Action required: Upgrade macOS 13 devices to maintain Teams desktop access [MC1308857] 4 pexels pixabay 163036](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-pixabay-163036-150x150.webp)
![Microsoft 365 Copilot (including Copilot Chat): Admin notifications for Copilot mobile app on macOS [MC1308856] 5 pexels pixabay 290470](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-pixabay-290470-150x150.webp)
