AWS artifact high security documentation change
Summary
Documented IAM policy update restricting organizations:EnableAWSServiceAccess to AWS Artifact
Security assessment
Explicitly reduces permissions scope following principle of least privilege, a security best practice. This change prevents broader service access permissions while maintaining functionality.
Diff
diff --git a/artifact/latest/ug/doc-history.md b/artifact/latest/ug/doc-history.md index 8181ae836..25c8c829c 100644 --- a//artifact/latest/ug/doc-history.md +++ b//artifact/latest/ug/doc-history.md @@ -10,0 +11 @@ Change| Description| Date +Updated AWSArtifactAgreementsFullAccess managed policy| Updated [AWSArtifactReportsReadOnlyAccess](security-iam-awsmanpol.html) managed policy to scope `organizations:EnableAWSServiceAccess` permissions down to AWS Artifact's service principal. This does not impact the managed policy's functionality.| October 16, 2025