49 sessions
- Chalk talk400 - ExpertIdentity and Access ManagementWednesday, Jun 182:00 p.m. Wednesday, Jun 18In this chalk talk, learn how policy evaluation works in detail and walk through some advanced AWS Identity and Access Management (IAM) policy evaluation scenarios. Discover how request context is evaluated, explore delegation patterns AWS services use to make requests, understand various condition keys and their optimal use, and receive recommendations for use of each policy type.Session Type: Chalk talkLevel: 400 - ExpertTrack: Identity and Access Management
- Chalk talk400 - ExpertIdentity and Access ManagementTuesday, Jun 1712:00 p.m. Tuesday, Jun 17In this chalk talk, learn how policy evaluation works in detail and walk through some advanced AWS Identity and Access Management (IAM) policy evaluation scenarios. Discover how request context is evaluated, explore delegation patterns AWS services use to make requests, understand various condition keys and their optimal use, and receive recommendations for use of each policy type.Session Type: Chalk talkLevel: 400 - ExpertTrack: Identity and Access Management
- Builders' session300 - AdvancedIdentity and Access ManagementWednesday, Jun 182:00 p.m. Wednesday, Jun 18Learn how to manage secure authentication of machines running in external, hybrid, or multicloud environments to AWS using AWS IAM Roles Anywhere. This session showcases trusted authentication patterns for environments spanning AWS and other environments such as on-premises networks, Azure, or GCP. Through live demonstrations, explore configuring trust anchors, managing X.509 certificates, and implementing secure authentication flows from external environments to AWS services. Discover production-ready patterns for certificate lifecycle management, security monitoring, and automated credential rotation. Leave with practical knowledge for implementing IAM Roles Anywhere in your hybrid architectures. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Identity and Access Management
- Lightning talk200 - IntermediateIdentity and Access ManagementAWS Directory ServiceAWS IAM Identity Center10:00 a.m. Wednesday, Jun 18Wednesday, Jun 18Join the AWS Directory Service team for a technical deep dive into AWS Managed Microsoft AD. Learn how to seamlessly extend your existing Active Directory to AWS, reducing management overhead while enabling key services like Amazon RDS, Amazon FSx, Amazon EC2, and Amazon WorkSpaces. Through live demonstrations, we'll show you how to deploy directories across multiple AWS regions and accounts with just a few clicks. You'll discover best practices for modernizing hybrid identity infrastructure and scaling directory services to meet enterprise needs. Perfect for infrastructure architects and identity administrators looking to optimize their AD deployment.Session Type: Lightning talkLevel: 200 - IntermediateTrack: Identity and Access Management
- Workshop300 - AdvancedIdentity and Access ManagementAmazon Cognito1:00 p.m. Monday, Jun 16Monday, Jun 16Learn how to use Amazon Cognito for your solutions’ CIAM needs. Use hands-on examples to build fully functional solutions and see some of the new features now supported natively in action like managed login UI, passwordless logins, and more. You must bring your laptop to participate.Session Type: WorkshopLevel: 300 - AdvancedTrack: Identity and Access Management
- Workshop300 - AdvancedIdentity and Access ManagementGenerative AIAgentic AICloud Security SpecialistData ScientistDeveloper / EngineerAmazon BedrockAmazon CognitoAWS Identity and Access Management (IAM)Cross-Industry SolutionsWednesday, Jun 1812:00 p.m. Wednesday, Jun 18As organizations deploy generative AI agents, homogeneously managing identities and permissions becomes even more critical for security and compliance. This technical session deconstructs the identity architecture of AI agents, examining how they interact with AWS services and third-party applications. Through this session, explore token exchange workflows for AI agent authentication, Lambda function security patterns and best practices, API authentication strategies for agent-to-service communication, and delegation mechanisms that can maintain end-user context and permissions. You must bring your laptop to participate.Session Type: WorkshopLevel: 300 - AdvancedTrack: Identity and Access Management
- Workshop300 - AdvancedIdentity and Access ManagementGenerative AIAgentic AICloud Security SpecialistData ScientistDeveloper / EngineerAmazon BedrockAmazon CognitoAWS Identity and Access Management (IAM)Cross-Industry SolutionsMonday, Jun 1610:00 a.m. Monday, Jun 16As organizations deploy generative AI agents, homogeneously managing identities and permissions becomes even more critical for security and compliance. This technical session deconstructs the identity architecture of AI agents, examining how they interact with AWS services and third-party applications. Through this session, explore token exchange workflows for AI agent authentication, Lambda function security patterns and best practices, API authentication strategies for agent-to-service communication, and delegation mechanisms that can maintain end-user context and permissions. You must bring your laptop to participate.Session Type: WorkshopLevel: 300 - AdvancedTrack: Identity and Access Management
- Lightning talk300 - AdvancedIdentity and Access ManagementAgentic AIAmazon CognitoAmazon Verified Permissions8:00 a.m. Wednesday, Jun 18Wednesday, Jun 18AI agents execute tasks for humans, operating independently with or without human presence, while collaborating seamlessly across on-premise and multi-cloud environments. This dynamic setup poses unique challenges in human/agent authentication, identity propagation/delegation, and resource authorization. Leverage Amazon Cognito, Amazon Verified Permissions, and Amazon Bedrock to master effective Identity and Access Management (IAM) for your AI agents. Through real-world examples using OAuth2-based identity management, machine-to-machine authentication, and policy-based access control, you’ll unlock the ability to scale complex agent interactions securely, empowering you to build robust, scalable Agentic AI solutions.Session Type: Lightning talkLevel: 300 - AdvancedTrack: Identity and Access Management
- Builders' session300 - AdvancedIdentity and Access ManagementAWS Identity and Access Management (IAM)AWS OrganizationsAWS PrivateLinkTuesday, Jun 173:00 p.m. Tuesday, Jun 17Are you looking to prevent unintended access to your data and mitigate data exposure risks? This hands-on session will demonstrate how data perimeter controls implemented through service control policies (SCPs), resource control policies (RCPs), and VPC endpoint policies can help ensure your corporate data remains within organizational boundaries. You'll build data perimeter policies for real-life security scenarios and validate their effectiveness using an assessment tool. By the end of this session, you'll have gained practical knowledge on how to ensure only trusted identities can access trusted resources from expected networks. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Identity and Access Management
- Builders' session300 - AdvancedIdentity and Access ManagementAWS Identity and Access Management (IAM)AWS OrganizationsAWS PrivateLinkWednesday, Jun 181:00 p.m. Wednesday, Jun 18Are you looking to prevent unintended access to your data and mitigate data exposure risks? This hands-on session will demonstrate how data perimeter controls implemented through service control policies (SCPs), resource control policies (RCPs), and VPC endpoint policies can help ensure your corporate data remains within organizational boundaries. You'll build data perimeter policies for real-life security scenarios and validate their effectiveness using an assessment tool. By the end of this session, you'll have gained practical knowledge on how to ensure only trusted identities can access trusted resources from expected networks. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Identity and Access Management
- Breakout session300 - AdvancedIdentity and Access ManagementTuesday, Jun 173:00 p.m. Tuesday, Jun 17Organizations aim to balance agility with security, particularly when empowering developers to manage their workloads and associated permissions. In this session, Comcast shares how they leverage resource control policies (RCPs) alongside other identity controls like permissions boundaries, service control policies, and AWS IAM Access Analyzer features to achieve this balance. As a global media and technology company providing broadband, wireless, and entertainment services, Comcast demonstrates how these tools enable rapid development while maintaining strong centralized security controls. RCPs, a new IAM feature, allow organizations to implement centralized guardrails governing resource access across their AWS organization.Session Type: Breakout sessionLevel: 300 - AdvancedTrack: Identity and Access Management
- Breakout session300 - AdvancedIdentity and Access ManagementAWS Identity and Access Management (IAM)Tuesday, Jun 174:00 p.m. Tuesday, Jun 17Wolters Kluwer, a global provider of professional information, software solutions, and services and GoTo Technologies (formerly LogMeIn Inc.), a U.S.-based software company that provides cloud-based remote work tools for collaboration and IT management use AWS IAM Access Analyzer to simplify and accelerate their journey to least privilege. Join this session to learn more about their use cases and their journey to empower their builders to refine IAM policies to remove excessive permissions. Gain insights into their strategies, best practices, and lessons learned for continuously monitoring unused permissions across their organization and building processes to streamline remediations.Session Type: Breakout sessionLevel: 300 - AdvancedTrack: Identity and Access Management
- Breakout session300 - AdvancedIdentity and Access ManagementCloud Security SpecialistData EngineerDeveloper / EngineerAWS Identity and Access Management (IAM)AWS OrganizationsWednesday, Jun 1811:00 a.m. Wednesday, Jun 18Organizations are storing an unprecedented and increasing amount of data on AWS for a range of use cases including data lakes, analytics, machine learning, and enterprise applications. They want to make sure that sensitive non-public data is protected from unintended access. In this session, dive deep into the controls that you can use to create a data perimeter to help ensure that only your trusted identities are accessing trusted resources from expected networks. Hear from Block, Inc. a leading fintech company about how they use data perimeter controls in their AWS environment to meet their security objectives.Session Type: Breakout sessionLevel: 300 - AdvancedTrack: Identity and Access Management
- Chalk talk300 - AdvancedIdentity and Access ManagementTuesday, Jun 171:00 p.m. Tuesday, Jun 17Building a robust AWS identity foundation requires moving beyond static credentials. This session deep dives into proven patterns for implementing dynamic, temporary access across your AWS organization. We'll explore real-world challenges of access key dependencies and share practical approaches to transition towards ephemeral credentials using IAM roles, AWS IAM Identity Center, and SAML federation. Through practical examples and lessons learned, discover how to implement secure authentication patterns that scale while reducing operational overhead. Walk away with actionable strategies to strengthen your identity perimeter and modernize your access management approach.Session Type: Chalk talkLevel: 300 - AdvancedTrack: Identity and Access Management
- Chalk talk300 - AdvancedIdentity and Access Management4:00 p.m. Monday, Jun 16Monday, Jun 16Building a robust AWS identity foundation requires moving beyond static credentials. This session deep dives into proven patterns for implementing dynamic, temporary access across your AWS organization. We'll explore real-world challenges of access key dependencies and share practical approaches to transition towards ephemeral credentials using IAM roles, AWS IAM Identity Center, and SAML federation. Through practical examples and lessons learned, discover how to implement secure authentication patterns that scale while reducing operational overhead. Walk away with actionable strategies to strengthen your identity perimeter and modernize your access management approach.Session Type: Chalk talkLevel: 300 - AdvancedTrack: Identity and Access Management
- Breakout session100 - FoundationalIdentity and Access ManagementWell-Architected FrameworkZero TrustCloud Security SpecialistIT Professional / Technical ManagerSystem AdministratorAWS IAM Identity CenterAWS Identity and Access Management (IAM)Cross-Industry Solutions11:00 a.m. Monday, Jun 16Monday, Jun 16To reduce the risk of cloud identity-based threats you must secure all identities, human and machine, by removing excessive permissions and enforcing least-privilege. CIEM solutions are good for this. But your developers and admins have legitimate needs for elevated privileges. Unfortunately, once granted, access is often forgotten – putting your cloud environment in danger. Leran how CIEM and Just- In-Time (JIT) access work together to achieve least privilege. We will explore applying entitlements management to detect and remediate permissions risk, using cases for applying JIT time bound access including with IdP groups and Audit reporting and simplified licensing business value. This presentation is brought to you by Tenable, an AWS Partner.Session Type: Breakout sessionLevel: 100 - FoundationalTrack: Identity and Access Management
- Builders' session300 - AdvancedIdentity and Access ManagementZero TrustAmazon Cognito8:00 a.m. Wednesday, Jun 18Wednesday, Jun 18Ready to break free from the distributed monolith? In this session, build production-ready patterns for implementing comprehensive Zero Trust controls from application entry points through to your service mesh. You'll create a secure service architecture using Amazon VPC Lattice and Amazon IAM, then implement differentiated access controls: API Gateway for customer-facing services and Amazon Verified Access for employee applications, where access decisions incorporate user context, device posture, and behavioral signals. Working with provided templates, you'll decompose a shared environment into properly isolated services, implement fine-grained authorization using Amazon Verified Permissions, and establish secure service-to-service communication patterns. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Identity and Access Management
- Builders' session300 - AdvancedIdentity and Access ManagementZero TrustAmazon CognitoMonday, Jun 1610:00 a.m. Monday, Jun 16Ready to break free from the distributed monolith? In this session, build production-ready patterns for implementing comprehensive Zero Trust controls from application entry points through to your service mesh. You'll create a secure service architecture using Amazon VPC Lattice and Amazon IAM, then implement differentiated access controls: API Gateway for customer-facing services and Amazon Verified Access for employee applications, where access decisions incorporate user context, device posture, and behavioral signals. Working with provided templates, you'll decompose a shared environment into properly isolated services, implement fine-grained authorization using Amazon Verified Permissions, and establish secure service-to-service communication patterns. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Identity and Access Management
- Lightning talk300 - AdvancedIdentity and Access ManagementAmazon API GatewayAmazon BedrockAWS IAM Identity CenterTuesday, Jun 174:00 p.m. Tuesday, Jun 17Platform teams often struggle with onboarding users to Single Sign-On (SSO), leading to support tickets, frustration, and delayed access to critical resources. The complexity of SSO setups and need for guidance create bottlenecks, straining IT resources. In this session, learn how a generative AI chatbot transformed IAM Identity Center onboarding by providing 24/7, personalized assistance. Users simply interact in natural language, receive step-by-step guidance, real-time answers, validation, and even automated setup. This reduced IT burden, streamlined onboarding, and accelerated user adoption and productivity.Session Type: Lightning talkLevel: 300 - AdvancedTrack: Identity and Access Management
- Breakout session300 - AdvancedIdentity and Access ManagementAmazon Verified Permissions4:00 p.m. Monday, Jun 16Monday, Jun 16MongoDB is an open-source NoSQL database. In 2024, MongoDB built a new access management system for Atlas, their database-as-a-service product, to provide fine-grained authorization for systems administrators managing database clusters. Attendees will learn why MongoDB selected Cedar, how it compares with similar technologies, and their journey to modernize their legacy RBAC system using Cedar and Amazon Verified Permissions. The session will explain how to design, implement, and test a performant and scalable policy-based access control solution. By using Cedar, MongoDB benefits from proven security and can add new policies to update permissions without needing to modify their code.Session Type: Breakout sessionLevel: 300 - AdvancedTrack: Identity and Access Management
- Chalk talk500 - DistinguishedIdentity and Access ManagementProvable SecurityAcademic / ResearcherCloud Security SpecialistAWS IAM Access AnalyzerWednesday, Jun 1811:00 a.m. Wednesday, Jun 18This session goes deep on how AWS turned a core formal methods technique into a practical security feature. We'll walk through the "Stratified Abstraction of Access Control Policies" paper that powers IAM Access Analyzer's external and cross-account access findings. Along the way, we'll learn how to read and understand technical research papers. You'll hear directly from the researchers who wrote the paper and the engineers who built the product, with opportunities to question and interact with them. This session connects computer science theory to real-world cloud security, making it valuable for those seeking an insider's view of AWS security research and development.Session Type: Chalk talkLevel: 500 - DistinguishedTrack: Identity and Access Management
- Workshop300 - AdvancedIdentity and Access ManagementAmazon AthenaAmazon RedShiftAWS IAM Identity CenterTuesday, Jun 1712:00 p.m. Tuesday, Jun 17This hands-on workshop explores AWS IAM Identity Center's Trusted Identity Propagation, teaching participants how to enable secure identity propagation across integrated applications. Through practical exercises, attendees will learn to configure identity propagation and use it with services such as Amazon Redshift, Amazon Q Business, and more. Participants will gain experience with cross-account scenarios, audit logging configuration, and troubleshooting common integration challenges. You must bring your laptop to participate.Session Type: WorkshopLevel: 300 - AdvancedTrack: Identity and Access Management
- Breakout session300 - AdvancedIdentity and Access ManagementNewly announced contentOpen SourceZero TrustCloud Security SpecialistDeveloper / EngineerDevOps EngineerAmazon Verified PermissionsWednesday, Jun 184:00 p.m. Wednesday, Jun 18Discover how Amazon Verified Permissions simplifies authorization for applications. Learn how Verified Permissions offers centralized policy management, simplifies auditing, and eliminates operational overhead for authorization at scale. This session introduces the verified-permissions-express-toolkit, an open-source package that helps organizations externalize authorization logic, improving security and reducing code complexity. We'll demonstrate implementing common authorization patterns, such as role-based and attribute-based access control. Join us to learn how to secure applications and APIs built on the Express.js framework in just five steps using Cedar policies and the new Express.js integration. Walk away with actionable knowledge to implement fine-grained permissions in your applications.Session Type: Breakout sessionLevel: 300 - AdvancedTrack: Identity and Access Management
- Builders' session300 - AdvancedIdentity and Access ManagementAmazon CloudWatchAmazon CognitoAWS CloudTrailService Quotas4:00 p.m. Monday, Jun 16Monday, Jun 16In this builders' session, gain hands-on experience on how to operationalize your Amazon Cognito user pools, protect your user pool from common security threats (e.g. credential stuffing attacks, bot attacks, logins from OFAC countries, lack of MFA, etc.), and misconfigurations. Establish observability and build a dashboard to monitor key risk indicators and quota usage. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Identity and Access Management
- Workshop300 - AdvancedIdentity and Access ManagementDevSecOpsAWS Identity and Access Management (IAM)AWS IAM Access Analyzer3:00 p.m. Wednesday, Jun 18Wednesday, Jun 18Learn how to implement automated IAM policy validation at scale in this hands-on workshop. Designed for cloud security engineers and DevOps practitioners, participants will build a CI/CD pipeline using GitHub, AWS CodePipeline, and AWS CodeBuild to validate IAM policies in AWS CloudFormation templates. Through guided labs, you'll learn to use AWS IAM Access Analyzer's policy validation and access preview APIs, implement the IAM Policy Validator for AWS CloudFormation, and optionally extend validation using AWS CloudFormation Guard. Leave with practical knowledge to help your development teams write and validate secure IAM policies before deployment. You must bring your laptop to participate.Session Type: WorkshopLevel: 300 - AdvancedTrack: Identity and Access Management
- Breakout session200 - IntermediateIdentity and Access Management10:00 a.m. Wednesday, Jun 18Wednesday, Jun 18Size is a factor of complexity. JPMorganChase (JPMC), a leading global financial services firm offering banking, investment, asset management, and payment solutions, is a large AWS customer with thousands of accounts across multiple AWS organizations, and is subject to strong security expectations from both their customers and their regulators. In this session, learn how JPMC improved the security of their AWS accounts, simplified operations, and saved countless hours of operator time by removing root user credentials from their AWS accounts.Session Type: Breakout sessionLevel: 200 - IntermediateTrack: Identity and Access Management
- Chalk talk300 - AdvancedIdentity and Access ManagementAmazon CognitoAWS IAM Identity CenterAWS Identity and Access Management (IAM)8:00 a.m. Wednesday, Jun 18Wednesday, Jun 18Some enterprises, such as those handling regulated data, must operate across multiple AWS Regions and partitions to meet regulatory requirements. While partitions built for specialized workloads provide isolation, organizations often need secure cross-Region access for centralized operations and monitoring. This session demonstrates proven patterns for managing authentication between Regions and partitions including those in AWS GovCloud (US) and the upcoming AWS European Sovereign Cloud, enabling scenarios such as follow-the-sun operations while maintaining compliance. Through real-world examples from public sector and regulated industries, attendees will learn strategies for implementing least-privilege, time-bound access controls across partition boundaries, including automated operations.Session Type: Chalk talkLevel: 300 - AdvancedTrack: Identity and Access Management
- Lightning talk200 - IntermediateIdentity and Access ManagementWell-Architected FrameworkAutomationDevSecOpsBusiness ExecutiveCloud Security SpecialistTech ExplorerAWS IAM Identity CenterAWS Identity and Access Management (IAM)AWS Identity and Access Management Access AnalyzerFinancial ServicesSoftware & Internet2:00 p.m. Tuesday, Jun 17Tuesday, Jun 17In this session, hear how KKR stopped chasing IAM issues and started automating access across their AWS environment. They set up just-in-time permissions, cut out unused access, and took control of third-party risk, all without slowing anyone down or deleting anything. No disruption, no tickets, no waiting. What they thought would take six months to clean up, took just six days. You'll leave with real-world ideas for saving time, reducing risk, and keeping your cloud in check - without all the manual work. This presentation is brought to you by Sonrai Security, an AWS Partner.Session Type: Lightning talkLevel: 200 - IntermediateTrack: Identity and Access Management
- Chalk talk300 - AdvancedIdentity and Access ManagementAWS Identity and Access Management (IAM)AWS OrganizationsTuesday, Jun 173:00 p.m. Tuesday, Jun 17Preventive Security allows organizations to reduce the likelihood of an unexpected action. In this session, we’ll explore the distinctions between Service Control Policies (SCPs), Resource Control Policies (RCPs), declarative policies, and VPC endpoint policies and how each policy type can be used in concrete examples. We will guide you through selecting the right policy to secure your AWS Organization and network infrastructure and you will learn from our best practices for enforcing these policies, ensuring they are effectively applied, tested, and scalable across your organization.Session Type: Chalk talkLevel: 300 - AdvancedTrack: Identity and Access Management
- Code talk300 - AdvancedIdentity and Access ManagementAmazon CognitoAmazon Verified PermissionsAWS Identity and Access Management (IAM)AWS LambdaTuesday, Jun 171:00 p.m. Tuesday, Jun 17This session focuses on transforming an existing application from role-based access control (RBAC) to policy-based access control (PBAC) using Amazon Verified Permissions (AVP) and Cedar policy. The drive for least privilege has led to role explosion in RBAC model and necessitates a shift towards PBAC, augmenting RBAC with attribute-based access control (ABAC). You will learn how to move authorization logic out of application code and implementing a centralized PBAC model. Attendees will also learn to define permissions as policies using Cedar and seamlessly migrate from RBAC to PBAC with minimal application logic changes, enabling more granular and scalable access control.Session Type: Code talkLevel: 300 - AdvancedTrack: Identity and Access Management
- Lightning talk200 - IntermediateIdentity and Access ManagementMigrationAmazon Cognito1:00 p.m. Monday, Jun 16Monday, Jun 16Digital transformation often requires modernizing customer identity and access management (CIAM) to improve security and user experience. This process can benefit from technologies like Amazon Cognito, a fully managed CIAM service that provides the security and scale enterprises need. In this session, learn how cloud security company Wiz leveraged Amazon Cognito for their migration strategy, achieving FedRAMP authorization, 99.9% availability, and a 70% reduction in IAM costs. Gain insights from their journey and learn best practices to enhance security and user experience in your own digital transformation.Session Type: Lightning talkLevel: 200 - IntermediateTrack: Identity and Access Management
- Chalk talk300 - AdvancedIdentity and Access ManagementCloud Security SpecialistData EngineerIT Professional / Technical ManagerAmazon RedShiftAWS IAM Identity CenterAWS Lake FormationFinancial ServicesGovernmentHealthcare & Life Sciences10:00 a.m. Wednesday, Jun 18Wednesday, Jun 18In this chalk talk session, we will explore the essential aspects of securing your AWS data lake and lakehouse, focusing on managing user identity and implementing fine-grained access control at scale. We'll delve into key AWS services such as Amazon Redshift, Amazon Athena, Amazon EMR, AWS Glue, and AWS Lake Formation, with a strong emphasis on leveraging AWS IAM Identity Center integration using Trusted Identity Propagation to enhance security. The discussion will also cover the implications of Data Mesh architecture, where centralized catalogs meet decentralized data consumption, enabling robust access control through AWS Lake Formation.Session Type: Chalk talkLevel: 300 - AdvancedTrack: Identity and Access Management
- Chalk talk300 - AdvancedIdentity and Access ManagementAmazon API GatewayAmazon CognitoAWS Lambda1:00 p.m. Monday, Jun 16Monday, Jun 16Unlock the power of secure machine-to-machine (M2M) authorization using Amazon Cognito's OAuth2 client credentials flow. This session dives deep into implementing M2M authorization, featuring real-world optimization strategies for both security and cost. Learn essential security best practices, multi-tenant reference architectures, and monitoring techniques that ensure your M2M usage remains efficient and secure. Whether you're building microservices, handling API authorization, or scaling your distributed systems, this session will equip you with actionable insights and patterns for successful M2M implementations. Bring your challenges and questions for an interactive discussion on Cognito-powered M2M authorization.Session Type: Chalk talkLevel: 300 - AdvancedTrack: Identity and Access Management
- Lightning talk200 - IntermediateIdentity and Access ManagementAgentic AIAWS Secrets ManagerTuesday, Jun 174:00 p.m. Tuesday, Jun 17Developers have to manage many sensitive secrets and credentials. 1Password can help developers build securely on AWS infrastructure, including for new agentic AI use cases. This demo will show how 1Password is simplifying secrets management for developers. This presentation is brought to you by 1Password, an AWS Partner.Session Type: Lightning talkLevel: 200 - IntermediateTrack: Identity and Access Management
- Chalk talk400 - ExpertIdentity and Access ManagementAmazon SageMakerAWS Key Management Service (AWS KMS)AWS Secrets ManagerMonday, Jun 1610:00 a.m. Monday, Jun 16Join this chalk talk for a behind-the-scenes peek at how requests to AWS services are authenticated and authorized and allow you to scale access control to over a billion requests a second. Dive into how policy evaluation is performed, how certain condition keys (e.g. Data Perimeter controls) are applied at the time of a request's authorization, and how these details could impact the way you write IAM policies. We'll aim to instill a deeper understanding of how AWS applies its culture of security to provide secure management of identities and resources through access to its services.Session Type: Chalk talkLevel: 400 - ExpertTrack: Identity and Access Management
- Chalk talk400 - ExpertIdentity and Access ManagementAmazon SageMakerAWS Key Management Service (AWS KMS)AWS Secrets ManagerTuesday, Jun 174:00 p.m. Tuesday, Jun 17Join this chalk talk for a behind-the-scenes peek at how requests to AWS services are authenticated and authorized and allow you to scale access control to over a billion requests a second. Dive into how policy evaluation is performed, how certain condition keys (e.g. Data Perimeter controls) are applied at the time of a request's authorization, and how these details could impact the way you write IAM policies. We'll aim to instill a deeper understanding of how AWS applies its culture of security to provide secure management of identities and resources through access to its services.Session Type: Chalk talkLevel: 400 - ExpertTrack: Identity and Access Management
- Builders' session400 - ExpertIdentity and Access ManagementGenerative AIAmazon BedrockAmazon CognitoAmazon Verified PermissionsWednesday, Jun 184:00 p.m. Wednesday, Jun 18Want to secure generative AI applications accessing your organizational data? Learn how to implement intelligent access controls for Amazon Bedrock-powered applications accessing your organizational data. In this builders' session, you'll build a defense-in-depth approach that combines authentication using Amazon Cognito and fine-grained authorization with Amazon Verified Permissions to secure access for Bedrock AI agents. Implement layered permissions that protect sensitive data without limiting your GenAI capabilities. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 400 - ExpertTrack: Identity and Access Management
- Builders' session400 - ExpertIdentity and Access ManagementGenerative AIAmazon BedrockAmazon CognitoAmazon Verified PermissionsTuesday, Jun 174:00 p.m. Tuesday, Jun 17Want to secure generative AI applications accessing your organizational data? Learn how to implement intelligent access controls for Amazon Bedrock-powered applications accessing your organizational data. In this builders' session, you'll build a defense-in-depth approach that combines authentication using Amazon Cognito and fine-grained authorization with Amazon Verified Permissions to secure access for Bedrock AI agents. Implement layered permissions that protect sensitive data without limiting your GenAI capabilities. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 400 - ExpertTrack: Identity and Access Management
- MeetupIdentity and Access ManagementAgentic AI2:00 p.m. Tuesday, Jun 17Tuesday, Jun 17Join peers to discuss evolving IAM challenges in a world of AI agents, automated workloads, and human users. Share approaches for implementing least-privilege access, managing machine identities, and securing service-to-service authentication. Exchange experiences with modern identity tools like AWS IAM Identity Center, Cognito, and Verified Permissions. Learn how organizations are adapting their IAM strategies for AI/ML workloads while maintaining security and compliance.Session Type: MeetupTrack: Identity and Access Management
- MeetupIdentity and Access ManagementAgentic AIWednesday, Jun 182:00 p.m. Wednesday, Jun 18Join peers to discuss evolving IAM challenges in a world of AI agents, automated workloads, and human users. Share approaches for implementing least-privilege access, managing machine identities, and securing service-to-service authentication. Exchange experiences with modern identity tools like AWS IAM Identity Center, Cognito, and Verified Permissions. Learn how organizations are adapting their IAM strategies for AI/ML workloads while maintaining security and compliance.Session Type: MeetupTrack: Identity and Access Management
- Lightning talk200 - IntermediateIdentity and Access ManagementCulture of SecurityDevSecOpsContainer/Serverless SecurityCloud Security SpecialistDevOps EngineerSolution / Systems ArchitectAWS Identity and Access Management (IAM)AWS Secrets ManagerAWS Systems ManagerCross-Industry SolutionsFinancial ServicesRetail & Consumer Goods6:00 p.m. Monday, Jun 16Monday, Jun 16Machine identities - from containers and Lambda to AI agents - vastly outnumber human users in AWS, making secrets and access management more complex and risky. Siloed practices can’t keep up with cloud speed, creating vulnerabilities and blind spots. In this session, explore a unified approach to securing machine identities in AWS using real-world use cases. Learn how to gain visibility with CyberArk Secrets Scanner, centralize secrets management with Secrets Hub, and enforce just-in-time, least privilege access with Secure Cloud Access - all without disrupting developer workflows or toolchains. This presentation is brought to you by CyberArk, an AWS Partner.Session Type: Lightning talkLevel: 200 - IntermediateTrack: Identity and Access Management
- Builders' session400 - ExpertIdentity and Access ManagementAmazon CognitoAmazon Elastic Kubernetes Service (Amazon EKS)Amazon Verified PermissionsAWS Identity and Access Management (IAM)Elastic Load Balancing (ELB)2:00 p.m. Monday, Jun 16Monday, Jun 16Managing access control per application in Kubernetes can quickly become complex and error-prone. Discover how to centralize and simplify authorization for containerized applications using Amazon Verified Permission with Kubernetes native constructs. By the end of this hands-on session you will learn on how to configure Amazon Verified Permissions and how to integrate it with Kubernetes Ingress controller. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 400 - ExpertTrack: Identity and Access Management
- Builders' session400 - ExpertIdentity and Access ManagementAmazon CognitoAmazon Elastic Kubernetes Service (Amazon EKS)Amazon Verified PermissionsAWS Identity and Access Management (IAM)Elastic Load Balancing (ELB)8:00 a.m. Wednesday, Jun 18Wednesday, Jun 18Managing access control per application in Kubernetes can quickly become complex and error-prone. Discover how to centralize and simplify authorization for containerized applications using Amazon Verified Permission with Kubernetes native constructs. By the end of this hands-on session you will learn on how to configure Amazon Verified Permissions and how to integrate it with Kubernetes Ingress controller. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 400 - ExpertTrack: Identity and Access Management
- Code talk400 - ExpertIdentity and Access ManagementGenerative AIAgentic AI4:00 p.m. Monday, Jun 16Monday, Jun 16Generative AI agents run tasks on behalf of human users and often interact with each other across on-premises environments and different cloud providers. This brings new challenges in identity authentication, propagation, delegation, and resource authorization in the overall agentic AI solution. Learn how Amazon Cognito's OAuth2-based identity management, machine-to-machine authentication, combined with Amazon Verified Permissions fine-grained authorization can enable secure delegation patterns for AI agents, while preserving human identity and consent, agent machine identity, and other request context throughout the agent chain. We will walk through real-world examples with agents built on Amazon Bedrock or other frameworks.Session Type: Code talkLevel: 400 - ExpertTrack: Identity and Access Management
- Code talk400 - ExpertIdentity and Access ManagementGenerative AIAgentic AITuesday, Jun 174:00 p.m. Tuesday, Jun 17Generative AI agents run tasks on behalf of human users and often interact with each other across on-premises environments and different cloud providers. This brings new challenges in identity authentication, propagation, delegation, and resource authorization in the overall agentic AI solution. Learn how Amazon Cognito's OAuth2-based identity management, machine-to-machine authentication, combined with Amazon Verified Permissions fine-grained authorization can enable secure delegation patterns for AI agents, while preserving human identity and consent, agent machine identity, and other request context throughout the agent chain. We will walk through real-world examples with agents built on Amazon Bedrock or other frameworks.Session Type: Code talkLevel: 400 - ExpertTrack: Identity and Access Management
- Breakout session300 - AdvancedIdentity and Access ManagementNewly announced contentCulture of SecurityProvable SecurityZero TrustCloud Security SpecialistDeveloper / EngineerIT ExecutiveAWS IAM Access AnalyzerCross-Industry SolutionsWednesday, Jun 182:00 p.m. Wednesday, Jun 18Are you looking to understand who has access to your business-critical AWS resources? Join this session to learn how new capabilities in IAM Access Analyzer can help you discover all roles and users that have access granted to your selected S3, DynamoDB, or RDS resources. We will demo how Access Analyzer collectively analyzes all your IAM policies and generates findings for possible access, regardless of whether access has previously occurred. Learn how the unified dashboard can provide 360-degree view of access granted to your resources and help with remediation. Essential for security architects and cloud security engineers managing AWS environments.Session Type: Breakout sessionLevel: 300 - AdvancedTrack: Identity and Access Management
- Code talk300 - AdvancedIdentity and Access ManagementAmazon NeptuneAWS IAM Identity CenterAWS Identity and Access Management Access Analyzer10:00 a.m. Wednesday, Jun 18Wednesday, Jun 18Discover how to gain deep insights into workforce identity relationships and resource access patterns by visualizing AWS IAM Identity Center data using graph databases. Learn how you can explore complex identity relationships, permission inheritance and resource access across your organization; get practical approaches to ingestion of identity data, creating graph queries for security analysis, and building visualization dashboards to identify potential resource access risks. We'll explore real-world scenarios for detecting excessive permissions, analyzing group memberships and resource access, and tracking resource access rights changes over time to strengthen your identity security posture.Session Type: Code talkLevel: 300 - AdvancedTrack: Identity and Access Management
- Breakout session300 - AdvancedIdentity and Access ManagementGenerative AISecurity AnalyticsWednesday, Jun 182:00 p.m. Wednesday, Jun 18Managing secure, consistent workforce access for generative AI and analytics is critical for unlocking innovation while protecting sensitive data. In this demo-filled session, you’ll see how centralized identity management and trusted identity propagation can deliver a user-centric data access experience. You’ll also learn how AWS IAM Identity Center simplifies access to AWS services such as Amazon Redshift, Amazon Athena, and AWS Lake Formation, while enabling fine-grained access to data based on user identity to help meet your security and compliance needs.Session Type: Breakout sessionLevel: 300 - AdvancedTrack: Identity and Access Management
- Code talk300 - AdvancedIdentity and Access ManagementZero TrustAmazon Elastic Kubernetes Service (Amazon EKS)AWS Identity and Access Management (IAM)AWS Private Certificate AuthorityWednesday, Jun 182:00 p.m. Wednesday, Jun 18Learn how to implement Zero Trust principles in Amazon EKS, moving beyond traditional perimeter defenses to secure modern Kubernetes environments. Discover EKS Pod Identity for streamlined workload identity management and explore secure service-to-service communication using service mesh technologies. Through architectural insights and live demonstrations, understand practical patterns for connecting pods to AWS services using identity-based permissions. This session provides essential knowledge for both newcomers and experienced practitioners to enhance their Kubernetes security posture with Zero Trust principles.Session Type: Code talkLevel: 300 - AdvancedTrack: Identity and Access Management