AWS IAM Identity Federation Now Supports External Services in European Sovereign Cloud
AWS Identity and Access Management (IAM) now supports outbound identity federation for workloads in the AWS European Sovereign Cloud (Germany). This new capability enables secure authentication with third-party cloud providers, SaaS applications, and self-hosted services using short-lived JSON Web Tokens (JWTs). It eliminates the need for long-term credentials and complex workarounds, helping customers meet evolving sovereignty requirements within the EU. Administrators can control token generation and properties via IAM policies and audit usage with CloudTrail logs for enhanced security and compliance.
Features (1) ›
- Outbound Identity Federation in AWS European Sovereign Cloud
AWS IAM now enables workloads within the AWS European Sovereign Cloud (Germany) to authenticate securely with external services using short-lived JSON Web Tokens. This capability simplifies integration with third-party cloud providers, SaaS applications, and self-hosted systems, while allowing administrators to enforce token properties via IAM policies and audit usage with CloudTrail.
https://aws.amazon.com/about-aws/whats-new/2026/08/aws-iam-european-sovereign-cloud/
Related releases
- AWS Lambda functions now support full IAM resource-based policies AWS What's New ·
- Amazon EKS now supports multiple external OIDC identity providers per cluster AWS What's New ·
- Amazon DynamoDB Streams now supports attribute-based access control (ABAC) AWS What's New ·
- AWS Partner Central agents MCP Server now supports OAuth with AWS Sign-In AWS What's New ·
- AWS IAM Increases Default Managed Policies Per Role to 20 AWS What's New ·
- AWS details external web access for Amazon Bedrock's Web Search AWS What's New ·