AWS Security ChangesHomeSearch

AWS dms: Add confused deputy trust-policy guidance for DMS service roles

Service: dms · 2026-09-27 · Documentation medium

File: dms/latest/userguide/security-iam.md · Type: iam

Summary

Adds an Important note stating that AWS DMS assumes the dms-vpc-role, dms-cloudwatch-logs-role and related service roles, and instructs adding aws:SourceAccount (or aws:SourceArn) to each role's trust policy to help prevent the cross-service confused deputy problem.

Security assessment

Documents an IAM trust-policy hardening control (aws:SourceAccount/aws:SourceArn conditions) that restricts which principals/accounts can have DMS assume the service roles, reducing cross-service confused deputy risk; it is preventive security documentation rather than a fix tied to a specific CVE or incident.

Evidence

+AWS DMS assumes these roles on your behalf. To help protect against the cross-service confused deputy problem, add the `aws:SourceAccount` global condition context key to each role's trust policy, so that AWS DMS can assume the role only for resources in your own account. To limit access to a single resource, use `aws:SourceArn` instead. For more information, see [IAM roles to use with AWS DMS API for cross-service confused deputy prevention](./cross-service-confused-deputy-prevention.html#cross-service-confused-deputy-prevention-dms-api).

Diff

diff --git a/dms/latest/userguide/security-iam.md b/dms/latest/userguide/security-iam.md
index b6ceb1f59..0609c4f42 100644
--- a//dms/latest/userguide/security-iam.md
+++ b//dms/latest/userguide/security-iam.md
@@ -302,0 +303,4 @@ You must use these exact role names as shown: `dms-vpc-role`, `dms-cloudwatch-lo
+###### Important
+
+AWS DMS assumes these roles on your behalf. To help protect against the cross-service confused deputy problem, add the `aws:SourceAccount` global condition context key to each role's trust policy, so that AWS DMS can assume the role only for resources in your own account. To limit access to a single resource, use `aws:SourceArn` instead. For more information, see [IAM roles to use with AWS DMS API for cross-service confused deputy prevention](./cross-service-confused-deputy-prevention.html#cross-service-confused-deputy-prevention-dms-api).
+