AWS Security ChangesHomeSearch

AWS AWSEC2: Reorganize serial console prerequisites; move Windows SAC to separate page

Service: AWSEC2 · 2026-09-27 · Documentation low

File: AWSEC2/latest/UserGuide/ec2-serial-console-prerequisites.md

Summary

Removes the Windows Special Admin Console (SAC) enablement instructions and the note about SAC breaking EC2 launch agents from the prerequisites page, replacing them with a cross-reference to a dedicated SAC troubleshooting page. Also minor wording fixes ("the Special Admin Console").

Security assessment

The change is purely editorial/structural: it relocates Windows SAC configuration steps to another page and rewords a sentence. No vulnerability, credential, encryption, or access-control content is introduced or fixed.

Evidence

-Use the instructions for your instance's operating system to configure your chosen troubleshooting tool.

Diff

diff --git a/AWSEC2/latest/UserGuide/ec2-serial-console-prerequisites.md b/AWSEC2/latest/UserGuide/ec2-serial-console-prerequisites.md
index ff2255ebf..21ca6938c 100644
--- a//AWSEC2/latest/UserGuide/ec2-serial-console-prerequisites.md
+++ b//AWSEC2/latest/UserGuide/ec2-serial-console-prerequisites.md
@@ -127 +127 @@ If the instance uses Amazon EC2 Systems Manager, then SSM Agent version 3.0.854.
-To troubleshoot your instance using the serial console, you can use GRUB or SysRq on Linux instances, and Special Admin Console (SAC) on Windows instances. Before you can use these tools, you must first perform configuration steps on every instance on which you'll use them.
+To troubleshoot your instance using the serial console, you can use GRUB or SysRq on Linux instances, and the Special Admin Console (SAC) on Windows instances. Before you can use these tools, you must first perform configuration steps on every instance on which you'll use them.
@@ -129 +129 @@ To troubleshoot your instance using the serial console, you can use GRUB or SysR
-Use the instructions for your instance's operating system to configure your chosen troubleshooting tool.
+Use the following instructions to configure GRUB or SysRq on a Linux instance. For Windows instances, to enable and use SAC, see [Troubleshoot your Windows instance using SAC](./troubleshoot-windows-sac.html).
@@ -299,57 +298,0 @@ This setting will clear on the next reboot.
-###### Note
-
-If you enable SAC on an instance, the EC2 services that rely on password retrieval will not work from the Amazon EC2 console. Windows on Amazon EC2 launch agents (EC2Config, EC2Launch v1, and EC2Launch v2) rely on the serial console to execute various tasks. These tasks do not perform successfully when you enable SAC on an instance. For more information about Windows on Amazon EC2 launch agents, see [Configure your Amazon EC2 Windows instance](./ec2-windows-instances.html). If you enable SAC, you can disable it later. For more information, see [Disable SAC and the boot menu](./troubleshoot-using-serial-console.html#disable-sac-bootmenu).
-
-Use one of the following methods to enable SAC and the boot menu on an instance.
-
-PowerShell
-    
-
-###### To enable SAC and the boot menu on a Windows instance
-
-  1. [Connect](./connecting_to_windows_instance.html) to your instance and perform the following steps from an elevated PowerShell command line.
-
-  2. Enable SAC.
-    
-        bcdedit /ems '{current}' on
-    bcdedit /emssettings EMSPORT:1 EMSBAUDRATE:115200
-
-  3. Enable the boot menu.
-    
-        bcdedit /set '{bootmgr}' displaybootmenu yes
-    bcdedit /set '{bootmgr}' timeout 15
-    bcdedit /set '{bootmgr}' bootems yes
-
-  4. Apply the updated configuration by rebooting the instance.
-    
-        shutdown -r -t 0
-
-
-
-
-Command prompt
-    
-
-###### To enable SAC and the boot menu on a Windows instance
-
-  1. [Connect](./connecting_to_windows_instance.html) to your instance and perform the following steps from the command prompt.
-
-  2. Enable SAC.
-    
-        bcdedit /ems {current} on
-    bcdedit /emssettings EMSPORT:1 EMSBAUDRATE:115200
-
-  3. Enable the boot menu.
-    
-        bcdedit /set {bootmgr} displaybootmenu yes
-    bcdedit /set {bootmgr} timeout 15
-    bcdedit /set {bootmgr} bootems yes
-    
-
-  4. Apply the updated configuration by rebooting the instance.
-    
-        shutdown -r -t 0
-
-
-
-