# What this digest covers
AWS Security published 20 posts in August 2026 across seven categories. The month concentrated on identity and access (five posts), data protection (four posts), and AI security (four posts), plus additional material on threat detection, governance, and networking. The posts include new features, migration timelines, implementation patterns, and hands-on examples.
# Identity and access highlights
- AWS Managed Microsoft AD: A retrospective notes 10 years of the managed AD offering and mentions Standard, Enterprise, and Hybrid editions, multi-Region replication, and integrations with 20+ AWS services.
- Sign-in experience: AWS is rolling out a redesigned sign-in page with a unified email entry point, social identity provider options, and an updated session selection flow for managing multiple active sessions.
- Access feature now supports VPCs without internet connectivity by routing console traffic (authentication, static assets, service API calls) through PrivateLink endpoints.
- IAM Identity Center governance: A post shows how to deploy event-driven discovery and reporting for IAM Identity Center applications and assignments, enabling near real-time governance checks and naming convention validation.
# Data protection and certificates
- KMS data key caching: Authors present approaches for multi-tenant envelope encryption at scale, including a hierarchical keyring pattern and a Caffeine-based cache approach to reduce KMS calls and cost while avoiding cache-stampede issues.
- AWS Certificate Manager (ACM): ACME protocol support is now available to automate public certificate issuance and renewal with standard clients (Certbot, cert-manager) and enterprise controls for domain scoping and visibility.
- S3 over-permissioned buckets: Guidance shows how to detect and remediate over-permissioned S3 buckets across multi-account environments using Lambda, AWS Config, and Security Hub, with automation for continuous monitoring.
- ACM email validation deprecation: AWS will discontinue email-validated public certificates on September 30, 2027. The post outlines the timeline and migration advice to DNS validation.
# AI security and agent integrations
- AgentCore Gateway: A request Lambda interceptor pattern shows how to integrate legacy authentication (for example Basic Auth) with AgentCore Gateway while keeping credentials in Secrets Manager instead of agent code.
- Propagating authorization: Guidance explains how to pass user identity through Amazon Bedrock AgentCore to downstream services (DynamoDB, knowledge bases, Salesforce) so agents enforce least-privilege without embedding authorization logic.
- Guardrails to manage tool interactions within agent workflows.
# Quick operational takeaways
- If you use Cognito and previously relied on support tickets for rate limits, you can now scale limits yourself in minutes.
- Migrate ACM email-validated certificates to DNS validation well before Sept 30, 2027 to avoid service disruption.
- For multi-tenant systems using envelope encryption, consider the hierarchical keyring or caching patterns to cut KMS costs while preventing cache stampedes.
# Where to look next
Read the individual posts linked in the August digest for code samples, deployment patterns, and step-by-step migration guidance on the items summarized above.