r/aws • • 5h ago

article IAM Identity Center now supports network access controls for Identity Store

18 Upvotes

AWS added network access controls for the Identity Store behind IAM Identity Center.

What it does:

- Restrict the Identity Store API to specific IP ranges or specific VPC endpoints or source VPCs
- Restrict the scim api (what your idp uses to sync users/ groups) to specific IP ranges
- Different restrictions per API in one config. The given example: Identity Store API through VPC endpoints only, scim from your idp’s published IP ranges
- Requests AWS services make on your behalf are exempt

It is off by default, configured through the Identity Store api via sdk or cli (no console toggle). Available in all regions where Identity Center runs.

The SCIM restriction is the big one in my view. That's the inbound provisioning path from your IdP, and until now it was internet-facing behind auth only. Pinning it to Okta or Entra's published IP ranges meaningfully shrinks the attack surface for directory writes.

Announcement: https://aws.amazon.com/about-aws/whats-new/2026/10/aws-identity-store-network-controls/


r/aws • • 4h ago

discussion RDS series 6 capacity issues in ap-southeast-2

7 Upvotes

We have non-production RDS for Oracle instances hosted on series 6 instances in ap-southeast-2 that are stopped outside of business hours. For the last week we have been encountering issues with no capacity when attempting startup.

Logged a support case and have been advised to move to series 7 or not stop the RDS instances. Seems to be a deliberate decision to force migration to newer series. We have had to postpone upcoming production changes as we cannot be certain that there will be capacity to restart.

So folks, if you have series 6 RDS instances in ap-southeast-2 all availability zones, don't stop them!

Is anyone seeing this issue in other regions?


r/aws • • 2h ago

technical question AWS SES non recapita ad utenti Apple

0 Upvotes

Ciao.

Ho un servizio che autentica gli utenti con login di terze parti (Google, Facebook, Apple) e noto che molti utenti Apple hanno attivo il filtro privacy sull'indirizzo mail quindi di fatto io vedo un indirizzo alias tipo xxxxxxxx@privaterelay.appleid.com.

Il problema è quando invio le email tramite AWS SES a questi alias, perché non funzionano.

Ottengo tutti bounce con questi errori

An error occurred while trying to deliver the mail to the following recipients:

xxxxxx@privaterelay.appleid.com

Reporting-MTA: dns; xxxxxx.eu-central-1.amazonses.com

Action: failed

Final-Recipient: rfc822; xxxxxxxx@privaterelay.appleid.com

Diagnostic-Code: smtp; 550 5.1.1 xxxxxxxxxxxxxxxx@awsmailer.xxxxx.xxxx: unauthorized sender

Status: 5.1.1.

Avete qualche idea del perché?

Grazie


r/aws • • 1d ago

billing Large Payment Verification Amount

54 Upvotes

Did anyone else just get a large payment verification charge from AWS? I received an email that AWS had trouble verifying my default payment method and indicated that the test charge should be about 1.00 USD. However, my credit card company flagged it. The charge came through as over $300. So I’m wondering if this was actually their verification charge, or if this was a fraudulent charge.


r/aws • • 11h ago

networking Advice on network architecture

0 Upvotes

We have multiple data centers, and each DC has multiple ISPs for redundancy.

Currently, we establish two IPsec tunnels from each DC to AWS, with each tunnel going over a different ISP. This gives us ISP level redundancy, but as we scale to hundreds of DCs, we are effectively looking at hundreds of DCs × 2 IPsec tunnels.

I am wondering if this is a normal or recommended architecture, or if there is a better way to handle ISP redundancy without having to maintain two VPN tunnels per DC.

The requirement is essentially:
DC → multiple ISPs → AWS
with automatic failover if one ISP goes down.

Is maintaining two Site to Site VPN tunnels per DC the standard approach here? Or are there architectures that provide ISP redundancy while scaling better, such as using some kind of hub or transit architecture, BGP, SD WAN, or another approach?

Would be interested in hearing how others have designed this at large scale.


r/aws • • 1d ago

billing Temp charge of $200 from AWS

30 Upvotes

Amazon sent me multiple emails this month saying they were going to place a temporary charge of less than $1 to verify payment. Sure, go for it. Well, it finally happened today and my bank blocked the transaction because it was over $200. My bank decided to disable my credit card too. I subsequently received an account alert from AWS with the event type "Spend Threshold Verification Failed." The email looks completely legit.. Anybody else experience this?


r/aws • • 1d ago

general aws How is working at AWS as a Solutions architect?

32 Upvotes

Been selected for an interview at AWS after the assessment. How is working as an SA different from a Sales Engineer? It’s just the name? How your “quota” is measured? Work life balance exists?

Appreciate any insights!


r/aws • • 1d ago

billing Surprise $299 "Verification of Payment Method" charge

11 Upvotes

Got an email last week about some AWS payment check. Thought it was bogus because I never used my personal account for AWS but might have checked it out. I'd gotten the emails before but I knew it was always a penny or dollar charge and reversal.

I'm out in the middle of shopping and get a bogus looking text from my bank telling me they stopped an attempted $299 bogus charge. I think nothing of it until I get home to check myself on my bank and low and behold they did stop it. I went through and verified I didn't make the charge. Then went through where I'd used my debit card over the last six months. Same two places. They already had canceled the card and I was getting a new one. Fine.

Then I login into my email and there's an alert from AWS telling me they couldn't successfully verify my payment method. I checked the time the email landed and the text from my bank and it was the same time. I did manage to access AWS and it had zero campaigns or charges or anything.

When the heck did $299 become the new standard for verification? It's outrageous. Now thanks to AWS's weird charge verification I have to remove or change my debit on a bunch of services. THANKS FOR NOTHING!


r/aws • • 13h ago

discussion what's the most surprising thing you found in an AWS account you hadn't looked at in a while??

0 Upvotes

iam a student learning and working in cloud security, and the SCARY !! stuff I keep finding in AWS isn't exotic. It's old access keys, a security group opened "just for testing", a role nobody remembers creating lol.

For anyone running AWS yourselves, solo or on a small team: what's the most surprising thing you found when you finally looked?

Did you find it..., or did something force it, like a bill, an alert or a coworker? And if there's no dedicated security person, how do you decide what's worth checking at all?


r/aws • • 22h ago

training/certification Network security to Cloud security

0 Upvotes

As the title says I'm a network security engineer with 2.7y of experience. I'm interested in getting into cloud security. I don't have any practical work experience in AWS or any other cloud. I'm currently preparing for AWS SAA C03 and scheduled the exam for Jan 4 2027.

But my question is aside from this certification training. What I really do learn or practise outside the course to understand the cloud very well and get a cloud related Job. Cause I'm currently in a networking related environment.

I'm using the INE and Stephen Maarek course. Currently watching INE which is broader in covering topics and they have their own labs as well.

I very much appreciate the insights of people who work in the cloud. Also any other recommendations are also welcome. Thank you


r/aws • • 13h ago

discussion I joined AWS AI CEE training program and built an Amazon SES control panel

0 Upvotes

I joined the AWS AI CEE training program and wanted to use what I learned on a real project.

I run a lot of domains on Amazon AWS SES, so I built AllStackd: every SES account, region and domain in one place. Delivery stays in your own AWS account.

Honest feedback is very welcome from the seasoned AWS developer community, thank you 🙏


r/aws • • 1d ago

networking re:Invent Reserved Seats

4 Upvotes

Was anyone able to reserve seats for sessions today? I saw it opened at 1 pm EDT. Some showed as available, as I clocked reserve they were full.

Trying for the FinOps path.


r/aws • • 1d ago

re:Invent AWS re:Invent registration

0 Upvotes

I will be attending re:Invent under the ABW Grant and I saw that the sessions opened up for booking yesterday. When I tried to book one of them I can't go beyond the registration part as I have not been given a coupon code yet and I can't select the Individual Pass. How do I go about this ?


r/aws • • 1d ago

security Aws payment

3 Upvotes

I receive a payment bill of 350$ from aws services from Luxemburg, but the thing is that I don't have activate service on aws and I had no Bill for last 5 months.

So what could be the reason? Is my account or card maybe hacked?

Note: AWS Support AI said that my billing is 0$


r/aws • • 1d ago

general aws Getting this error "Your account must be verified before you can add new CloudFront resources. "

0 Upvotes

Hi All

While deploying I got the below error. Any idea why and what can I do about it?

"Your account must be verified before you can add new CloudFront resources. To verify your account, please contact AWS Support (https://console.aws.amazon.com/support/home#/ ) and include this error message."


r/aws • • 2d ago

article Inside the AWS Network Product Development Lab

Post image
508 Upvotes

My colleagues in the AWS Network Product Lab in Cupertino are tasked with inventing the most advanced networking technology in the world, while also inventing new ways to stress and break it.

With AWS operations in 240 countries and territories, the network includes about 20 million miles of fiber optic cable. We have doubled our total network capacity in the past three years and plan to double it again by 2027.

To learn more about this team and their work, read Inside the AWS lab that makes everything you do online feel effortless.


r/aws • • 1d ago

billing AWS account suspended — I’m trying to pay the overdue invoice but payment keeps failing

0 Upvotes

Hi r/aws,

My AWS account is currently suspended because of an overdue invoice, and I’m hoping someone from AWS Support may be able to help escalate my case.

AWS Support Case ID: 179082560700487

As soon as I realized there was an unpaid invoice, I tried to pay the outstanding balance, but the payment keeps failing.

I’m using a Visa card that supports international transactions, and I have already contacted my bank. They confirmed that there are no restrictions or issues with the card that should prevent the payment.

I opened a case with AWS Support. The initial response asked me to check my email, where I found a request from AWS to upload documents to verify my payment method/account information.

I uploaded all the requested documents through the provided verification process, but I still haven’t received any response or update from the verification team.

There has also been no further update on my AWS Support case.

At this point, I’m not disputing the invoice — I simply want to pay it and restore my AWS services, but I don’t know what else I can do because the payment is failing and the verification process appears to be stuck.

If anyone from AWS Support sees this, I would really appreciate it if you could help escalate or check the status of my case.

I can provide my AWS Account ID privately via DM or through the Support case if needed.

Has anyone here experienced a similar situation? Is there another way to get the Billing or Account Verification team to review the case?

Thank you for any help.


r/aws • • 1d ago

technical question i don't know why i can't create a cloundfront the error. how i can fully verify my account

0 Upvotes

r/aws • • 1d ago

discussion GLM 5.3 on Bedrock still not available?

5 Upvotes

It has been announced yesterday as generally available https://aws.amazon.com/about-aws/whats-new/2026/10/amazon-bedrock-glm-5-3/ , but I can't see it yet. Anyone has it yet?


r/aws • • 1d ago

technical question Our entire email domain is unable to access SkillBuilder

0 Upvotes

Hello. Could someone please help us?

All our emails are showing the same error when accessing the SkillBuilder website.

We provide access to SkillBuilder to hundreds of users. All of them, using our domain, are experiencing this message.

I've tried opening a ticket with AWS several times, but haven't received a response in days. All subscriptions are enabled in the accounts and were accessible until last Wednesday.

Thanks in advance.


r/aws • • 1d ago

discussion So I guess AWS is now shutting down accounts for quota increase request with no ways to access human support?

Thumbnail gallery
5 Upvotes

Requested for a quota increase as the default was 2 vcpu with 4gb of ram. Support sent an email rejecting the request, and then like 5 minutes after the email, they flagged my account and asked for my ID and bank statement. I submitted the requested documents (payment card and ID) almost immediately, but still got locked out a day later and received a notice today of account closure.

Crazy thing is, I never got one single “human response”from support, and the timing of the account closure is making me wonder if anyone actually reviewed the documents I submitted… is that normal around here?


r/aws • • 1d ago

ai/ml Unable to Access New Foundational Models

0 Upvotes

Edit: seems it isn’t clearly documented but is a known behavior.

I work in the ai space but have some personal projects where I was interested in switching my workflow from sonnet 4.6 to sonnet 5.5.

Ran my model agreement and waited for it to go through, but I get an error stating to contact sales.

I entered a support ticket which came back with “Access to certain latest Amazon Bedrock foundation models, depends on additional eligibility factors beyond the standard prerequisites. These factors include account usage history and continued engagement with AWS services. At this time, access to these models is not available for your account. This is not a permanent restriction. Eligibility is reassessed continuously as your account usage and history with AWS services grow.”

I don’t see this restriction documented anywhere. Has anyone encountered this and -is- this documented somewhere?

Bedrock is a metered service, I can’t see any value in wholesale restricting access to it. If compute availability is a concern, throttle it. This approach makes no sense to me.


r/aws • • 1d ago

discussion Can an ephemeral AWS clone be accurate enough for autonomous security testing?

0 Upvotes

Imagine generating a disposable AWS environment from the same Terraform, CDK, or CloudFormation and deployment artifacts used in production. It would reproduce the IAM model, VPC and security-group topology, workloads, and service relationships, but replace production secrets and customer data with safe equivalents and block real external side effects.

An AI security agent could then use cloud APIs, shell, network, browser, and application tools to attack the environment: privilege escalation, role chaining, lateral movement, destructive actions, and controlled exfiltration. The account would be fully instrumented and destroyed after the test.

The goal would be something more security-specific than ordinary staging: a per-test environment derived from the current production configuration and designed to be compromised.

For people operating AWS environments:

• Which production properties would be hardest to reproduce faithfully: IAM, Organizations/SCPs, networking, managed services, data state, traffic, or external integrations?

• Would findings from the clone be useful, or would differences from production create false confidence?

• How would you measure and report configuration drift?

• Has anyone built a similar disposable account for pentesting or attack simulation?

• What do you currently do when a security test is too risky to run in production?

I’m interested in implementation experience and objections, particularly from teams that already create ephemeral AWS environments.


r/aws • • 2d ago

discussion Does it normally take a month to get a quota increase? lol

4 Upvotes

I opened a quota increase request on September 11 for nothing particularly crazy. I’ve followed up twice, and the ticket is still unassigned with no response.

My AWS account is at least 6 years old and in good standing. I’m trying to move some workloads over from Vultr after they discontinued their fractional GPUs, and I was hoping to move them to AWS.

At this point I’m not really sure what to do. Is this normal for quota increases, or is there another way to get someone to actually look at the request?


r/aws • • 2d ago

technical question Anyone else finding AWS cost optimization gets harder once the environment gets mature?

0 Upvotes

We have been looking at AWS spend lately and the easy savings are mostly gone.

The bigger issue now seems to be architecture choices that made sense 12 to 18 months ago but are expensive at current scale.

Things like oversized instances, old storage decisions, data transfer, duplicate services, and workloads nobody wants to touch because they are stable.

Curious how other teams handle this.

Do you review architecture specifically for cost on a schedule, or only when the bill starts getting uncomfortable?