Exploring the new AWS Sign Up experience
Wiz analyzed AWS's new sandboxed sign-up experience, finding it omits CloudTrail, blocks security services, and limits vendor IAM role access.
AWS's new sign-up experience creates three accounts in an Organization sandbox governed by SCPs and RCPs, with a $20/month budget that triggers a spend-limit SCP denying new compute workloads. Wiz found the sandbox lacks organization-level CloudTrail and its FreeTierSCP allowlist denies GuardDuty, Security Hub, Detective, Inspector, Macie, and Access Analyzer, while still permitting IAM users with access keys, public S3 buckets, and IMDSv1 EC2 instances. A remaining RCP blocks all principals outside the Organization, denying cross-account sts:AssumeRole and preventing vendor IAM role integrations until the account is upgraded. Wiz concludes the sandbox prioritizes simplicity and cost control over a strong security posture.