Amazon SageMaker notebooks now support trusted identity propagation

Amazon SageMaker Notebooks
Amazon SageMaker Notebooks now support Trusted Identity Propagation (TIP) with Amazon Athena, Amazon Redshift, and Amazon EMR Serverless, enabling per-user access control for data analytics.
When connected to a TIP-enabled compute in a TIP-enabled Project, each notebook user's IAM Identity Center identity flows through to AWS Lake Formation, ensuring they see only the tables, columns, and rows their permissions allow, without sharing a single broad execution role.
With TIP, enterprises get:
- Per-user data boundaries enforced based on who is running the query
- Full audit attribution with CloudTrail recording which user accessed data
- Reduced admin friction since identity propagates automatically through the existing compute connection with no extra login, token, or role management required
What to do
- Use a notebook in a TIP enabled Project with the supported engines
This feature is available in all AWS Regions where Amazon SageMaker Unified Studio is available. To learn more, see Trusted identity propagation in the Amazon SageMaker Unified Studio Administrator Guide and Notebooks in the Amazon SageMaker Unified Studio User Guide.
Source: AWS release notes
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



