AWS Security ChangesHomeSearch

AWS managedservices: Fix SAML claim rule regex to match 12-digit account ID

Service: managedservices · 2026-09-27 · Documentation medium

File: managedservices/latest/onboardingguide/fed-with-console.md · Type: authz

Summary

Corrected the ADFS claim rule regex from [^d]{12} to [\d]{12} in the condition and RegExReplace role ARN mapping for console federation.

Security assessment

Same SAML federation role-mapping regex fix; ensures the account ID is correctly parsed as 12 digits for IAM role ARN issuance. Authorization-relevant configuration correction, not a specific vulnerability.

Evidence

+        c:[Type == "http://temp/variable", Value =~ "(?i)^AWS-([\d]{12})-"]

Diff

diff --git a/managedservices/latest/onboardingguide/fed-with-console.md b/managedservices/latest/onboardingguide/fed-with-console.md
index 7e0295f61..8e642e853 100644
--- a//managedservices/latest/onboardingguide/fed-with-console.md
+++ b//managedservices/latest/onboardingguide/fed-with-console.md
@@ -42,2 +42,2 @@ After creating the relying party trust as per the blog post, configure the claim
-        c:[Type == "http://temp/variable", Value =~ "(?i)^AWS-([^d]{12})-"]
-     => issue(Type = "https://aws.amazon.com/SAML/Attributes/Role", Value = RegExReplace(c.Value, "AWS-([^d]{12})-", 
+        c:[Type == "http://temp/variable", Value =~ "(?i)^AWS-([\d]{12})-"]
+     => issue(Type = "https://aws.amazon.com/SAML/Attributes/Role", Value = RegExReplace(c.Value, "AWS-([\d]{12})-",