AWS Identity & Security Services Cheat Sheet

📌 Last Updated: June 2026 — Includes AWS Security Hub reimagined (re:Invent 2025), AWS Security Agent (GA March 2026), mandatory MFA enforcement for all root users, GuardDuty Extended Threat Detection, and IAM Identity Center multi-Region replication.
AWS Identity & Security Services Overview
AWS Security, Identity, and Compliance services provide a comprehensive set of tools to help protect data, accounts, and workloads. These services are organized into the following categories:
Identity and Access Management
- AWS Identity and Access Management (IAM) – Securely manage access to AWS services and resources using users, groups, roles, and policies
- AWS IAM Identity Center (formerly AWS SSO) – Centrally manage SSO access to multiple AWS accounts and business applications
- Now supports multi-Region replication (Feb 2026) for high availability
- Supports IPv6 dual-stack endpoints
- Amazon Cognito – Customer identity and access management (CIAM) for web and mobile apps
- Now supports passwordless authentication with passkeys (FIDO2/WebAuthn), email OTP, and SMS OTP (Nov 2024)
- New feature tiers: Essentials and Plus (Nov 2024)
- Managed Login for pre-built authentication UIs
- Amazon Verified Permissions – Scalable, fine-grained authorization using Cedar policy language for custom applications
- AWS Resource Access Manager (RAM) – Securely share AWS resources across accounts and within AWS Organizations
- AWS Directory Service – Managed Microsoft Active Directory in the AWS Cloud
Detection and Response
- Amazon GuardDuty – Intelligent threat detection that continuously monitors for malicious activity
- Extended Threat Detection (re:Invent 2024) – AI/ML-powered attack sequence identification across multiple data sources
- Now covers EC2, ECS, EKS, S3, and IAM attack sequences
- Custom entity lists for domain-based threat intelligence (Sept 2025)
- Amazon Detective – Analyze, investigate, and identify root cause of security findings using ML and graph theory
- Amazon Inspector – Automated vulnerability management for EC2 instances and container images in ECR
- AWS Security Hub – Cloud security posture management (CSPM) and unified security operations
- Reimagined at re:Invent 2025 – Unifies GuardDuty, Inspector, and other services into a single experience
- Near real-time analytics and risk prioritization (GA Dec 2025)
- Extended Plan (GA Feb 2026) – Full-stack enterprise security with 21 curated partner solutions across 9 categories
- Expanding to multicloud environments
- AWS Security Agent (GA March 2026) – AI-powered frontier agent for proactive application security
- Automated security reviews tailored to organizational requirements
- On-demand context-aware penetration testing
- Full repository code scanning (Preview May 2026)
- Operates like a human penetration tester – identifies, exploits, and validates vulnerabilities
Data Protection
Network and Application Protection
- AWS WAF – Web application firewall to protect against common web exploits and bots
- AWS Shield – Managed DDoS protection (Standard and Advanced tiers)
- AWS Network Firewall – Managed network firewall for VPC with stateful inspection and IPS
- AWS Firewall Manager – Centrally configure and manage firewall rules across accounts in AWS Organizations
Security Data Management and Compliance
- Amazon Security Lake – Centralize security data from AWS, SaaS, on-premises using OCSF standard
- Achieved FedRAMP High and Moderate authorization (April 2025)
- AWS Audit Manager – Continuously audit AWS usage for risk and compliance assessment
- AWS Artifact – On-demand access to AWS security and compliance reports
Key Updates (2024-2026)
- MFA Enforcement (2024-2025) – AWS now mandates MFA for all root users across all account types. Prevents over 99% of password-related attacks.
- AWS Security Hub Reimagined (re:Invent 2025) – Completely redesigned to unify security services into a single experience with near real-time analytics and AI-driven risk prioritization.
- AWS Security Agent (GA March 2026) – First AI-powered frontier agent for autonomous application security testing and code scanning.
- GuardDuty Extended Threat Detection (re:Invent 2024) – AI/ML attack sequence identification now covers EC2, ECS, EKS workloads.
- IAM Identity Center Multi-Region (Feb 2026) – Replicate identity center configuration across multiple AWS Regions for high availability.
- Amazon Cognito Passwordless (Nov 2024) – Native passkey support with FIDO2/WebAuthn, email OTP, and SMS OTP authentication.
- Centralized Root Access Management (Nov 2024) – Centrally manage root credentials and perform privileged tasks across AWS Organizations member accounts.
- Agentic AI Security Framework (2025) – New Agentic AI Security Scoping Matrix for securing autonomous AI systems.
AWS Certification Relevance
- Solutions Architect (Associate/Professional) – IAM, VPC security, encryption, Security Hub, GuardDuty
- Security Specialty – All services in depth, including Security Lake, Detective, Macie, Inspector
- SysOps Administrator – Security Hub, Config, GuardDuty, IAM best practices
- Developer Associate – Cognito, IAM roles, KMS, Secrets Manager
- DevOps Professional – Security automation, Inspector, Security Hub integrations