Amazon SageMaker Unified Studio updates to AWS managed policies
View details about updates to AWS managed policies for Amazon SageMaker Unified Studio since this service began tracking these changes. For automatic alerts about changes to this page, subscribe to the RSS feed on the Amazon SageMaker Unified Studio Document history page.
Change | Description | Date |
---|---|---|
Policy update - SageMakerStudioFullAccess |
Policy update - generalizing the scope for SecretsManager
|
7/23/2025 |
Policy update - SageMakerStudioEMRServiceRolePolicy |
Policy update - removing unwanted KMS permissions for EMR cluster AtRestEncryption in the Amazon SageMaker Unified Studio EmrOnEc2 blueprint and adding permissions for EMR clsuter to encrypt customer data using customer managed KMS for logs pushed to Amazon S3 bucket in Amazon SageMaker Unified Studio when using EmrOnEc2 blueprint with customer managed encryption. |
7/23/2025 |
Policy update - SageMakerStudioProjectRoleMachineLearningPolicy |
Policy updates to the SageMakerStudioProjectRoleMachineLearningPolicy - adding permissions to support cross-account Amazon S3 asset subscription fulfillment using Amazon S3 access grants. |
7/23/2025 |
Policy update - SageMakerStudioProjectProvisioningRolePolicy |
Policy updates to the SageMakerStudioProjectProvisioningRolePolicy
- adding permissions to create and manage Amazon S3 table buckets
and also adding permissions to automate S3 table analytics
integration flow within Amazon SageMaker Unified Studio. Also adding permissions to read
templates from users' S3 buckets and permissions to validate the
template using AWS Cloud Formation. Also adding permissions to get
and create an S3 access grant instance in the project account to
support managing subscriptions for S3 asset types. Also adding
|
7/15/2025 |
Policy update - SageMakerStudioProjectUserRolePolicy |
Policy update - adding permissions to allow deletion of AWS Glue
databases in Amazon Datalake, adding |
7/15/2025 |
New policy - SageMakerStudioAdminProjectUserRolePolicy |
New policy - This IAM policy grants an IAM role full access to the AWS Glue Data Catalog (metadata) and Amazon S3 (actual data) for the data lake operations, with access scoped by region, account, and role tags. |
7/15/2025 |
Policy update - SageMakerStudioBedrockKnowledgeBaseServiceRolePolicy |
Policy updates to the
SageMakerStudioBedrockKnowledgeBaseServiceRolePolicy - adding
|
7/15/2025 |
Policy update - SageMakerStudioProjectUserRolePolicy |
Policy update - adding permissions to access Amazon Athena default catalog resource. |
6/25/2025 |
Policy update - SageMakerStudioDomainExecutionRolePolicy |
Policy updates to the SageMakerStudioDomainExecutionRolePolicy -
adding support for the Amazon Q |
6/18/2025 |
Policy update - SageMakerStudioProjectUserRolePolicy |
Policy updates to the SageMakerStudioProjectUserRolePolicy - bring
back previously removed permission to |
6/13/2025 |
Policy update - SageMakerStudioProjectUserRolePolicy |
Policy updates to the SageMakerStudioProjectUserRolePolicy - adding permissions to list Amazon Bedrock foundation models. Removing permissions to terminate EMR Cluster, change security group rules, Amazon Athena default catalog permissions, and list S3 buckets permissions at bucket level. |
6/13/2025 |
Policy update - SageMakerStudioProjectProvisioningRolePolicy |
Policy updates to the SageMakerStudioProjectProvisioningRolePolicy - adding the untag role permission to fix project update failure. Also adding permissions to integrate with Amazon QuickSight. Also optimizing to reduce the policy size. And adding permissions to enable automatic sync of repositories. |
6/04/2025 |
Policy update - SageMakerStudioProjectUserRolePolicy |
Policy updates to the SageMakerStudioProjectUserRolePolicy - removing RedshiftDbUser format restriction. Adding KMS permissions required by dependent services for Federated Data Connection. Adding permissions to support Amazon QuickSight integration. |
6/04/2025 |
Policy update - AmazonDataZoneBedrockModelConsumptionPolicy |
Policy updates to the AmazonDataZoneBedrockModelConsumptionPolicy
- adding permissions to call the |
5/28/2025 |
Policy update - SageMakerStudioFullAccess |
Policy updates to the SageMakerStudioFullAccess - adding permissions to support attaching or updating AWS managed permissions in AWS RAM resource shares in the Amazon SageMaker console. |
5/22/2025 |
Policy update - AmazonDataZoneBedrockModelConsumptionPolicy |
Policy updates to the AmazonDataZoneBedrockModelConsumptionPolicy - adding support for the conversation history feature powered by Amazon Bedrock session management in generative AI playgrounds. |
5/13/2025 |
Policy update - SageMakerStudioProjectRoleMachineLearningPolicy |
Policy updates to the SageMakerStudioProjectRoleMachineLearningPolicy - as CodeEditor (VS Code) is introduced into Amazon SageMaker Unified Studio, users need the ability to create/delete CodeEditor space applications in Amazon SageMaker. Currently, only Amazon SageMaker space apps are allowed to be created with the JupyterLab app type. This change extends the current capability of creating/deleting JupyterLab space applications to CodeEditor (VS Code). |
5/01/2025 |
Policy update - SageMakerStudioProjectProvisioningRolePolicy |
Policy updates to the SageMakerStudioProjectProvisioningRolePolicy - adding IAM permissions for the AmazonSageMakerQueryExecution role to support query execution role creation during enabling of the Tooling blueprint. Adding the DeleteSchedule permission so that when projects are deleted, the Schedule Group can be deleted. EventBridge runs DeleteSchedule automatically on Schedule Groups when it attempts to delete them, regardless of whether the Schedule Group actually has schedules in it. This permission allows for that deleteSchedule call to be made during project deletion. |
4/28/2025 |
Policy update - SageMakerStudioProjectUserRolePolicy |
Policy updates to the SageMakerStudioProjectUserRolePolicy - adding permissions for integration with Amazon Bedrock Data Automation. Adding permissions to show Amazon Bedrock agent versions and their details to users. Adding permission to support Trusted Identity Propagation in QEv2. Ensuring project isolation for Amazon Bedrock Inline Agents. |
4/28/2025 |
Policy update - SageMakerStudioBedrockKnowledgeBaseServiceRolePolicy |
Policy updates to the SageMakerStudioBedrockKnowledgeBaseServiceRolePolicy - adding support for structured data sources in Amazon Bedrock knowledge bases for generative AI app development projects. |
4/16/2025 |
Policy update - SageMakerStudioBedrockFlowServiceRolePolicy |
Policy updates to the SageMakerStudioBedrockFlowServiceRolePolicy - adding support for using Amazon Bedrock agent nodes in Amazon Bedrock flows for generative AI app development projects. |
4/09/2025 |
Policy update - SageMakerStudioProjectUserRolePolicy |
Policy updates to the SageMakerStudioProjectUserRolePolicy - preventing sharing provisioned Amazon Redshift-Serverless across all projects. Adding EventBridge Scheduler permissions for users to create schedules in the project schedule group. Adding permissions to handle Amazon SageMaker Studio migration to Amazon SageMaker Unified Studio. Adding support for the Amazon SageMaker App type CodeEditor. |
4/09/2025 |
Policy update - SageMakerStudioProjectProvisioningRolePolicy |
Policy updates to the SageMakerStudioProjectProvisioningRolePolicy
- adding |
4/09/2025 |
Policy update - SageMakerStudioDomainExecutionRolePolicy |
Policy updates to the SageMakerStudioDomainExecutionRolePolicy - adding support for the GetUpdateEligibility API required by Amazon SageMaker Unified Studio to fetch update comments and determine project's eligibility for the workflow of updating projects. Also adding support for the existing Amazon DataZone Rule APIs required by Amazon SageMaker Unified Studio to mange and enforce rules. |
3/25/2025 |
Policy update - SageMakerStudioProjectUserRolePolicy |
Policy updates to the SageMakerStudioProjectUserRolePolicy - preventing default AWS Glue database from being listed as it causes issues with Spark SQL. Also adding permission to use new project-wide Amazon Bedrock service role for improved scalability. |
3/21/2025 |
Policy update - SageMakerStudioProjectProvisioningRolePolicy |
Policy updates to the SageMakerStudioProjectProvisioningRolePolicy - adding permission to describe stack event for better error reporting. |
3/21/2025 |
Policy update - SageMakerStudioBedrockFlowServiceRolePolicy |
Policy updates to the SageMakerStudioProjectProvisioningRolePolicy - adding KMS permissions to decrypt Amazon Bedrock guardrails attached to the Amazon Bedrock flows. |
3/10/2025 |
Policy update - SageMakerStudioProjectProvisioningRolePolicy |
Policy updates to the SageMakerStudioProjectProvisioningRolePolicy - adding permission to change trust policy during project update to address confused deputy problem. Also adding permission to attach PartnerApps policy to the user role. |
3/05/2025 |
Policy update - SageMakerStudioProjectProvisioningRolePolicy |
Policy updates to the SageMakerStudioProjectProvisioningRolePolicy - adding support for ProjectUpdate for EMR Serverless blueprint to proactively notify users on invalid updates on EMR Serverless application. |
3/04/2025 |
Policy update - SageMakerStudioProjectProvisioningRolePolicy |
Policy updates to the SageMakerStudioProjectProvisioningRolePolicy - renaming Amazon Bedrock tag and adding permission to remove deprecated tag on roles. |
2/28/2025 |
Policy update - SageMakerStudioProjectRoleMachineLearningPolicy |
Policy updates to the SageMakerStudioProjectRoleMachineLearningPolicy - adding support for the MLFlow Tracking Server for Shared VPC, applying visibility condition to Amazon SageMaker Search API. |
2/28/2025 |
Policy update - SageMakerStudioProjectUserRolePolicy |
Policy updates to the SageMakerStudioProjectUserRolePolicy -
changes to support shared VPC by removing ResourceAccount condition
on actions dependent on VPC/subnets. Moving permissions from inline
to this AWS managed policy for Amazon EMR, EMR-Serverless, and
federated connections. Adding support for buckets with public access
blocked with permission |
2/28/2025 |
Policy update - SageMakerStudioEMRServiceRolePolicy |
Policy updates to the SageMakerStudioEMRServiceRolePolicy - adding permissions to allow Amazon EMR to create network interfaces against Shared VPC. |
2/28/2025 |
New policy - SageMakerStudioEMRInstanceRolePolicy |
Amazon SageMaker Unified Studio creates IAM roles for project users to perform data analytics, artificial intelligence, and machine learning actions and uses this policy when creating these roles to define the permissions related to EMR. |
2/28/2025 |
New policy - SageMakerStudioBedrockFunctionExecutionRolePolicy |
This policy allows AWS Lambda to access an Amazon Bedrock function component's configuration in Amazon SageMaker Unified Studio. |
2/25/2025 |
New policy - SageMakerStudioBedrockKnowledgeBaseCustomResourcePolicy |
This policy provides access to configure vector stores and Amazon Bedrock knowledge bases in Amazon SageMaker Unified Studio. |
2/25/2025 |
New policy - SageMakerStudioBedrockKnowledgeBaseServiceRolePolicy |
This policy allows Amazon Bedrock Knowledge Bases to access Amazon Bedrock models and data sources in Amazon SageMaker Unified Studio. |
2/25/2025 |
Policy update - SageMakerStudioProjectProvisioningRolePolicy |
Policy updates to the SageMakerStudioProjectProvisioningRolePolicy
- adding permissions for batch grants in AWS LakeFormation to give
grants to IDC users. Adding various |
2/24/2025 |
New policy - SageMakerStudioBedrockEvaluationJobServiceRolePolicy |
This policy allows Amazon Bedrock to access Amazon Bedrock models and datasets for evaluation jobs in Amazon SageMaker Unified Studio. |
2/14/2025 |
New policy - SageMakerStudioBedrockPromptUserRolePolicy |
This policy provides access to an Amazon Bedrock prompt and its configuration in Amazon SageMaker Unified Studio. |
2/14/2025 |
New policy - SageMakerStudioBedrockFlowServiceRolePolicy |
This policy allows Amazon Bedrock Flows to access Amazon Bedrock models and other resources attached to a flow in Amazon SageMaker Unified Studio. |
2/14/2025 |
New policy - SageMakerStudioBedrockChatAgentUserRolePolicy |
This policy provides access to an Amazon Bedrock chat agent app's configuration and Amazon Bedrock agent in Amazon SageMaker Unified Studio. |
2/14/2025 |
New policy - SageMakerStudioBedrockAgentServiceRolePolicy |
This policy allows Amazon Bedrock Agents to access Amazon Bedrock models and other resources attached to an agent in Amazon SageMaker Unified Studio. |
2/14/2025 |
Policy update - SageMakerStudioProjectRoleMachineLearningPolicy |
Policy updates to the
SageMakerStudioProjectRoleMachineLearningPolicy - adding permission
for |
2/14/2025 |
New Policy - SageMakerStudioEMRServiceRolePolicy |
New policy SageMakerStudioEMRServiceRolePolicy - Amazon SageMaker Unified Studio creates IAM roles for project users to perform data analytics, artificial intelligence, and machine learning actions and uses this policy when creating these roles to define the permissions related to Amazon EMR. |
1/31/2025 |
New Policy - SageMakerStudioQueryExecutionRolePolicy |
New policy SageMakerStudioQueryExecutionRolePolicy - this is the default policy for the SageMakerQueryExecutionRole role. This policy provides permissions to run query executions on federated connections. |
1/31/2025 |
Policy update - SageMakerStudioProjectProvisioningRolePolicy |
Policy updates to SageMakerStudioProjectProvisioningRolePolicy - adding permissions to manage IAM roles with only AWS managed policies attached to them and no permissions boundary. Also adding permissions to update the AWS Lambda function for Amazon Athena federated connections. |
1/31/2025 |
Policy update - SageMakerStudioFullAccess |
Policy updates to SageMakerStudioFullAccess - updating the CodeConnections tagging permissions to support tagging for CodeConnections host resources in the Amazon SageMaker console. |
1/24/2025 |
Policy update - SageMakerStudioDomainExecutionRolePolicy |
Policy updates to SageMakerStudioDomainExecutionRolePolicy - adding support for the AWS CodeConnections APIs in order to make the Copy button available for self-managed Git providers. |
1/24/2025 |
Policy updates to SageMakerStudioProjectProvisioningRolePolicy |
Policy updates to SageMakerStudioProjectProvisioningRolePolicy - adding permissions to support CMK in CodeCommit, AWS Glue Catalog, and Amazon Redshift Serverless. |
12/18/2024 |
Policy updates to SageMakerStudioProjectUserRolePolicy. |
Policy updates to SageMakerStudioProjectUserRolePolicy - adding permissions to support CMK in CodeCommit, and AWS Glue Catalog. |
12/18/2024 |
Policy updates to SageMakerStudioProjectUserRolePermissionsBoundary |
Policy updates to SageMakerStudioProjectUserRolePermissionsBoundary - adding permissions to support CMK in CodeCommit, AWS Glue Catalog, Amazon Redshift Serverless, and EMR on EC2. |
12/18/2024 |
New policy - SageMakerStudioFullAccess |
Adding a new managed policy - this policy provides full access to Amazon SageMaker Unified Studio via the Amazon SageMaker management console. |
12/02/2024 |
New policy - SageMakerStudioProjectUserRolePermissionsBoundary |
Adding a new managed policy - SageMakerStudioProjectUserRolePermissionsBoundary. Amazon SageMaker Unified Studio creates IAM roles for Projects users to perform data analytics, artificial intelligence, and machine learning actions, and uses this policy when creating these roles to define the boundary of their permissions. |
12/02/2024 |
New policy - SageMakerStudioProjectProvisioningRolePolicy |
Adding a new managed policy - SageMakerStudioProjectProvisioningRolePolicy. Amazon SageMaker Unified Studio uses this policy to provision and manage resources in your account. |
12/02/2024 |
New policy - SageMakerStudioDomainExecutionRolePolicy |
Adding a new managed policy - SageMakerStudioDomainExecutionRolePolicy - Default policy for the SageMakerUnifiedStudioDomainExecutionRole service role. This role is used by Amazon SageMaker Unified Studio to catalog, discover, govern, share, and analyze data in the Amazon SageMaker Unified Studio domain. |
12/02/2024 |
New policy - SageMakerStudioDomainServiceRolePolicy |
Adding a new managed policy - SageMakerStudioDomainServiceRolePolic. This is the default policy for the SageMakerUnifiedStudioDomainServiceRole service role. This policy is used by Amazon SageMaker Unified Studio to access the SSM parameters in the user’s account. Those parameters are set by the administrator in the Amazon SageMaker Unified Studio project profiles. This policy also has permissions to AWS KMS for encrypted SSM parameters. The KMS key must be tagged with EnableKeyForAmazonDataZone to allow decrypting the SSM parameters. |
12/02/2024 |
New policy - SageMakerStudioProjectUserRolePolicy |
Adding a new managed policy - SageMakerStudioProjectUserRolePolicy. Amazon SageMaker Unified Studio creates IAM roles for projects users to perform data analytics, artificial intelligence, and machine learning actions, and uses this policy when creating these roles to define the permissions. |
12/02/2024 |
New policy - SageMakerStudioProjectRoleMachineLearningPolicy |
Adding a new managed policy - SageMakerStudioProjectRoleMachineLearningPolicy. Amazon SageMaker Unified Studio creates IAM roles for projects users to perform data analytics, artificial intelligence, and machine learning actions, and uses this policy when creating these roles to define the permissions. |
12/02/2024 |
New policy - AmazonDataZoneBedrockModelManagementPolicy |
Adding a new managed policy - AmazonDataZoneBedrockModelManagementPolicy - that provides permissions to manage Amazon Bedrock model access, including creating, tagging and deleting application inference profiles. |
12/02/2024 |
New policy - AmazonDataZoneBedrockModelConsumptionPolicy |
Adding a new managed policy - AmazonDataZoneBedrockModelConsumptionPolicy - that provides permissions to consume Amazon Bedrock models, including invoking Amazon Bedrock application inference profile created for particular Amazon DataZone domain. |
12/02/2024 |
Amazon SageMaker Unified Studio started tracking changes |
Amazon SageMaker Unified Studio started tracking changes for its AWS managed policies. |
December 2nd, 2024 |