<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Managed-Policy on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/managed-policy/</link><description>Recent content in Managed-Policy on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Tue, 02 Jun 2026 16:23:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/managed-policy/index.xml" rel="self" type="application/rss+xml"/><item><title>AWS SageMaker Studio Auto-IAM Policy: Security Review</title><link>https://zxcloudsecurity.co.uk/posts/aws-sagemaker-studio-auto-iam-policy-model-customization/</link><pubDate>Tue, 02 Jun 2026 16:23:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/aws-sagemaker-studio-auto-iam-policy-model-customization/</guid><description>SageMaker Studio now auto-attaches an IAM policy for model customisation. Security architects should audit this managed policy against least-privilege prin</description><content:encoded><![CDATA[<p>🟢 <strong>Low</strong>  |  <strong>Source:</strong> <a href="https://aws.amazon.com/about-aws/whats-new/2026/01/quick-setup-model-customization-sagemaker-studio/">AWS What&rsquo;s New</a></p>
<hr>
<p>Amazon SageMaker Studio&rsquo;s quick setup time has been reduced from over two minutes to under twenty seconds. New Studio environments now automatically receive a managed IAM policy granting serverless model customisation permissions, including fine-tuning, evaluation, and deployment to SageMaker or Bedrock endpoints. This reduces friction for ML practitioners but introduces pre-configured IAM permissions that security teams should review.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review the scope of the automatically attached AmazonSageMakerModelCustomizationCoreAccess managed policy against your least-privilege baselines — auto-provisioned IAM policies with deployment permissions to Bedrock and SageMaker endpoints may exceed what individual users or teams require. Consider whether your landing zone or Service Control Policies should restrict or audit automatic policy attachment in SageMaker Studio environments.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://aws.amazon.com/about-aws/whats-new/2026/01/quick-setup-model-customization-sagemaker-studio/">Amazon SageMaker Studio now sets up in seconds with model customization ready from the start</a></p>
]]></content:encoded></item></channel></rss>