AWS Security ChangesHomeSearch

AWS AWSEC2: Add Windows OS-level serial console access guidance

Service: AWSEC2 · 2026-09-27 · Documentation medium

File: AWSEC2/latest/UserGuide/configure-access-to-serial-console.md · Type: authz

Summary

Expands the OS-level serial console access section to cover Windows in addition to Linux, and adds a warning that granting serial console permissions is equivalent to granting admin-level privileges on the instance.

Security assessment

The added text explicitly warns that serial console access equates to admin-level privileges on the instance, which is privilege-escalation/authorization guidance for operators configuring IAM policies for serial console access. It documents a security-relevant access-control consideration rather than fixing a specific vulnerability.

Evidence

+Granting serial console permissions is equivalent to granting admin-level privileges on the instance. Further authentication is driven by Windows and you should consult Microsoft documentation for additional details.

Diff

diff --git a/AWSEC2/latest/UserGuide/configure-access-to-serial-console.md b/AWSEC2/latest/UserGuide/configure-access-to-serial-console.md
index 73eb8904d..77e1293bc 100644
--- a//AWSEC2/latest/UserGuide/configure-access-to-serial-console.md
+++ b//AWSEC2/latest/UserGuide/configure-access-to-serial-console.md
@@ -53 +53 @@ You can configure access at the user level by configuring an IAM policy to allow
-**OS level** (Linux instances only)
+**OS level**
@@ -55,0 +56,2 @@ You can configure access at the user level by configuring an IAM policy to allow
+  * **Linux**
+
@@ -57,0 +60,9 @@ You can set a user password at the guest OS level. This provides access to the s
+  * **Windows**
+
+Granting serial console permissions is equivalent to granting admin-level privileges on the instance. Further authentication is driven by Windows and you should consult Microsoft documentation for additional details.
+
+For more information, see the Microsoft docs at [Emergency Management Services Tools and Settings](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2003/cc787940\(v=ws.10\)).
+
+
+
+