Amazon Neptune adds IAM tag-based access control for data plane operations
Amazon Neptune now supports tag-based access control (TBAC) for IAM, allowing control over data-plane operations using resource and principal tags. This enhances security for large-scale deployments by enabling dynamic, attribute-based access management, reducing the need to manage individual cluster ARNs in policies. The feature is available in all AWS Regions for Neptune engine version 1.2.0.0 or later with IAM authentication enabled.
- →IAM tag-based access control for Neptune data-plane operations
- →Dynamic access governance and isolation
- →Availability and prerequisites
Features (1) ›
- IAM tag-based access control for Neptune data-plane operations
Amazon Neptune now supports tag-based access control (TBAC) enabling users to control access to data-plane operations using AWS resource tags and IAM principal tags in IAM policies and SCPs. This feature helps manage access dynamically without enumerating specific cluster ARNs.
Enhancements (1) ›
- Dynamic access governance and isolation
TBAC allows administrators to govern cluster access dynamically, restricting principals to clusters whose tags match their own, thus eliminating lateral access risk and enforcing team/environment-level isolation. It also supports federated identity workflows using SAML or OIDC session tags.
Notes (1) ›
- Availability and prerequisites
This feature is available in all AWS Regions where Amazon Neptune is offered. It requires Neptune engine version 1.2.0.0 or later and IAM authentication to be enabled.
https://aws.amazon.com/about-aws/whats-new/2026/07/amazon-neptune-tbac/
Related releases
- SageMaker Unified Studio Enhances Git Version Control Across Project Tools AWS What's New ·
- IAM Policy Simulator integrated into IAM console with new features AWS What's New ·
- AWS IAM Identity Center adds multi-Region replication for its own directory AWS What's New ·
- Amazon EKS supports AWS PrivateLink for OIDC endpoint AWS What's New ·
- Amazon Bedrock AgentCore enables unified observability for AI agents AWS What's New ·
- AWS CloudTrail enhances network activity event filtering by IAM identity AWS What's New ·