AWS Security ChangesHomeSearch

AWS AmazonRDS: Enforced rdsproxyadmin protection in MariaDB 12.3

Service: AmazonRDS · 2026-08-12 · Documentation medium

File: AmazonRDS/latest/UserGuide/rds-proxy.md · Type: authz

Summary

Documented engine-level enforcement preventing modification of rdsproxyadmin user.

Security assessment

Hardens security by preventing unauthorized changes to critical proxy management account.

Evidence

Starting in RDS for MariaDB version 12.3, the database engine enforces this protection. Attempts to `CREATE`, `DROP`, `RENAME`, `GRANT`, `REVOKE`, or `SET PASSWORD` for `rdsproxyadmin` return an error.

Diff

diff --git a/AmazonRDS/latest/UserGuide/rds-proxy.md b/AmazonRDS/latest/UserGuide/rds-proxy.md
index e21c3ea4c..177b8437b 100644
--- a//AmazonRDS/latest/UserGuide/rds-proxy.md
+++ b//AmazonRDS/latest/UserGuide/rds-proxy.md
@@ -101,0 +102,2 @@ For more information about global condition context keys, see [AWS global condit
+Starting in RDS for MariaDB version 12.3, the database engine enforces this protection. Attempts to `CREATE`, `DROP`, `RENAME`, `GRANT`, `REVOKE`, or `SET PASSWORD` for `rdsproxyadmin` return an error. For details, see [MariaDB security on Amazon RDS](./MariaDB.Concepts.UsersAndPrivileges.html).
+