ZeroHour
Product

Control Tower

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Exploring the new AWS Sign Up experience

Wiz analyzed AWS's new sandboxed sign-up experience, finding it omits CloudTrail, blocks security services, and limits vendor IAM role access.

AWS's new sign-up experience creates three accounts in an Organization sandbox governed by SCPs and RCPs, with a $20/month budget that triggers a spend-limit SCP denying new compute workloads. Wiz found the sandbox lacks organization-level CloudTrail and its FreeTierSCP allowlist denies GuardDuty, Security Hub, Detective, Inspector, Macie, and Access Analyzer, while still permitting IAM users with access keys, public S3 buckets, and IMDSv1 EC2 instances. A remaining RCP blocks all principals outside the Organization, denying cross-account sts:AssumeRole and preventing vendor IAM role integrations until the account is upgraded. Wiz concludes the sandbox prioritizes simplicity and cost control over a strong security posture.

Wiz Blog · 1d agoTools

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.