AWS Identity and Access Management (IAM) Roles Anywhere now provides the capability to configure Virtual Private Cloud (VPC) endpoint policies for the IAM Roles Anywhere CreateSession API. You can update your VPC endpoint policies to allow or deny the CreateSession operation. If CreateSession is not explicitly included in the Allow statement of your VPC endpoint policy or if you don’t allow all operations (for example, by specifying “rolesanywhere:*“ as the action), IAM Roles Anywhere will not return temporary AWS credentials for requests made through your VPC endpoint.
The CreateSession API enables workloads running outside of AWS to obtain temporary AWS credentials using X.509 certificates to access AWS resources. Previously, VPC endpoint policies applied to all IAM Roles Anywhere API operations except CreateSession. This launch closes that gap, giving you consistent, fine-grained access control across all IAM Roles Anywhere API operations.
This feature is available in all AWS Regions where IAM Roles Anywhere is available, including the AWS GovCloud (US) Regions, AWS European Sovereign Cloud (Germany) Region, and China Regions. To learn more, see the IAM Roles Anywhere User Guide.
Categories: general:products/aws-iam,marketing:marchitecture/security-identity-and-compliance
Source: Amazon Web Services
Latest Posts
- Learning Agent in Microsoft 365 Copilot to become generally available [MC1319212]
![Learning Agent in Microsoft 365 Copilot to become generally available [MC1319212] 2 pexels agk42 2599244.bak](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Interact with your favorite apps on Teams using Slash ( / ) Commands [MC1319214]
![Interact with your favorite apps on Teams using Slash ( / ) Commands [MC1319214] 3 woman 2101262 1920](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft Teams: In‑meeting toggle to turn Meeting AI on or off [MC1319216]
![Microsoft Teams: In‑meeting toggle to turn Meeting AI on or off [MC1319216] 4 pexels fox 58267 15685976](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft Outlook: External email tag now supported in Inbox Rules [MC1319208]
![Microsoft Outlook: External email tag now supported in Inbox Rules [MC1319208] 5 pexels michael pointner 134459625 25381383](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)

![Learning Agent in Microsoft 365 Copilot to become generally available [MC1319212] 2 pexels agk42 2599244.bak](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-agk42-2599244.bak_-150x150.webp)
![Interact with your favorite apps on Teams using Slash ( / ) Commands [MC1319214] 3 woman 2101262 1920](https://mwpro.co.uk/wp-content/uploads/2025/06/woman-2101262_1920-150x150.webp)
![Microsoft Teams: In‑meeting toggle to turn Meeting AI on or off [MC1319216] 4 pexels fox 58267 15685976](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-fox-58267-15685976-150x150.webp)
![Microsoft Outlook: External email tag now supported in Inbox Rules [MC1319208] 5 pexels michael pointner 134459625 25381383](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-michael-pointner-134459625-25381383-150x150.webp)
