AWS Identity & Security Services Cheat Sheet

📌 Last Updated: June 2026 — Includes AWS Security Hub reimagined (re:Invent 2025), AWS Security Agent (GA March 2026), mandatory MFA enforcement for all root users, GuardDuty Extended Threat Detection, and IAM Identity Center multi-Region replication.
AWS Identity Services Cheat Sheet
AWS Security Services Cheat Sheet
AWS Identity & Security Services Overview
AWS Security, Identity, and Compliance services provide a comprehensive set of tools to help protect data, accounts, and workloads. These services are organized into the following categories:
Identity and Access Management
- AWS Identity and Access Management (IAM) – Securely manage access to AWS services and resources using users, groups, roles, and policies
- AWS IAM Identity Center (formerly AWS SSO) – Centrally manage SSO access to multiple AWS accounts and business applications
- Now supports multi-Region replication (Feb 2026) for high availability
- Supports IPv6 dual-stack endpoints
- Amazon Cognito – Customer identity and access management (CIAM) for web and mobile apps
- Now supports passwordless authentication with passkeys (FIDO2/WebAuthn), email OTP, and SMS OTP (Nov 2024)
- New feature tiers: Essentials and Plus (Nov 2024)
- Managed Login for pre-built authentication UIs
- Amazon Verified Permissions – Scalable, fine-grained authorization using Cedar policy language for custom applications
- AWS Resource Access Manager (RAM) – Securely share AWS resources across accounts and within AWS Organizations
- AWS Directory Service – Managed Microsoft Active Directory in the AWS Cloud
Detection and Response
- Amazon GuardDuty – Intelligent threat detection that continuously monitors for malicious activity
- Extended Threat Detection (re:Invent 2024) – AI/ML-powered attack sequence identification across multiple data sources
- Now covers EC2, ECS, EKS, S3, and IAM attack sequences
- Custom entity lists for domain-based threat intelligence (Sept 2025)
- Amazon Detective – Analyze, investigate, and identify root cause of security findings using ML and graph theory
- Amazon Inspector – Automated vulnerability management for EC2 instances and container images in ECR
- AWS Security Hub – Cloud security posture management (CSPM) and unified security operations
- Reimagined at re:Invent 2025 – Unifies GuardDuty, Inspector, and other services into a single experience
- Near real-time analytics and risk prioritization (GA Dec 2025)
- Extended Plan (GA Feb 2026) – Full-stack enterprise security with 21 curated partner solutions across 9 categories
- Expanding to multicloud environments
- AWS Security Agent (GA March 2026) – AI-powered frontier agent for proactive application security
- Automated security reviews tailored to organizational requirements
- On-demand context-aware penetration testing
- Full repository code scanning (Preview May 2026)
- Operates like a human penetration tester – identifies, exploits, and validates vulnerabilities
Data Protection
- AWS Key Management Service (KMS) – Create and manage cryptographic keys using FIPS 140-2 validated HSMs
- AWS CloudHSM – Dedicated FIPS 140-2 Level 3 validated hardware security modules
- AWS Certificate Manager (ACM) – Provision, manage, and deploy SSL/TLS certificates
- Amazon Macie – Data security and privacy service using ML to discover and protect sensitive data in S3
- AWS Secrets Manager – Rotate, manage, and retrieve database credentials, API keys, and other secrets
Network and Application Protection
- AWS WAF – Web application firewall to protect against common web exploits and bots
- AWS Shield – Managed DDoS protection (Standard and Advanced tiers)
- AWS Network Firewall – Managed network firewall for VPC with stateful inspection and IPS
- AWS Firewall Manager – Centrally configure and manage firewall rules across accounts in AWS Organizations
Security Data Management and Compliance
- Amazon Security Lake – Centralize security data from AWS, SaaS, on-premises using OCSF standard
- Achieved FedRAMP High and Moderate authorization (April 2025)
- AWS Audit Manager – Continuously audit AWS usage for risk and compliance assessment
- AWS Artifact – On-demand access to AWS security and compliance reports
Key Updates (2024-2026)
- MFA Enforcement (2024-2025) – AWS now mandates MFA for all root users across all account types. Prevents over 99% of password-related attacks.
- AWS Security Hub Reimagined (re:Invent 2025) – Completely redesigned to unify security services into a single experience with near real-time analytics and AI-driven risk prioritization.
- AWS Security Agent (GA March 2026) – First AI-powered frontier agent for autonomous application security testing and code scanning.
- GuardDuty Extended Threat Detection (re:Invent 2024) – AI/ML attack sequence identification now covers EC2, ECS, EKS workloads.
- IAM Identity Center Multi-Region (Feb 2026) – Replicate identity center configuration across multiple AWS Regions for high availability.
- Amazon Cognito Passwordless (Nov 2024) – Native passkey support with FIDO2/WebAuthn, email OTP, and SMS OTP authentication.
- Centralized Root Access Management (Nov 2024) – Centrally manage root credentials and perform privileged tasks across AWS Organizations member accounts.
- Agentic AI Security Framework (2025) – New Agentic AI Security Scoping Matrix for securing autonomous AI systems.
AWS Certification Relevance
- Solutions Architect (Associate/Professional) – IAM, VPC security, encryption, Security Hub, GuardDuty
- Security Specialty – All services in depth, including Security Lake, Detective, Macie, Inspector
- SysOps Administrator – Security Hub, Config, GuardDuty, IAM best practices
- Developer Associate – Cognito, IAM roles, KMS, Secrets Manager
- DevOps Professional – Security automation, Inspector, Security Hub integrations
Please add more services here
AWS Shield
AWS Systems Manager
AWS GuardDuty
AWS Config
above are the few services to name
Sure, will be doing the same.
thanks! this is awesome.. but why is the WAF crossed out? Is the information outdated or has the service been retired entirely?
Thanks peter, the first half is relevant but cause of editor issues are crossed out. The Third party WAF is no more relevant now as it is provided as a managed service by AWS.
Thank you for sharing. This will give us a good starting point.
Your cheat sheets are really great and helpful. Good work Jayendra.
thanks, glad it helped
excellent work….thanks a lot
Thank you Jayendra, great work for the community.