← Back to all announcements
★★★☆☆ 22/05/2026

Amazon SageMaker expands domain management across domain types

IDC-based domain admins can now manage projects, roles, VPC settings, and cross-account access directly inside SageMaker Unified Studio—no AWS console required.

View original announcement →

Visual Summary

graph TD A{{SageMaker Domain Management}}:::announced B((Administrators)):::external C([Project Management]):::feature D([User & Permissions]):::feature E([VPC Configuration]):::feature F([Cross-Account Access]):::feature G(IAM Identity Center):::compute H(IAM Domains):::compute I(AWS Analytics & ML Services):::compute B ==>|"accesses portal"| A A -->|"create & manage"| C A -->|"configure"| D A -->|"inherits to projects"| E A -->|"associate accounts"| F A -->|"authenticates via"| G A -->|"supports"| H C -->|"execution roles"| I F -.->|"data sharing"| I classDef announced fill:#ff9900,stroke:#ec7211,color:#fff,font-weight:bold classDef compute fill:#e3f2fd,stroke:#1565c0,color:#1565c0 classDef storage fill:#e8f5e9,stroke:#2e7d32,color:#2e7d32 classDef feature fill:#fff3e0,stroke:#e65100,color:#e65100 classDef external fill:#f5f5f5,stroke:#616161,color:#616161

What's New

Amazon SageMaker Unified Studio has expanded its domain management capabilities to cover both Identity Center (IDC)-based and IAM-based domains, accessible directly from the Unified Studio portal rather than requiring the AWS console. Administrators of IDC-based domains can now create and manage projects, configure execution roles, manage users and permissions, set VPC networking properties, and manage cross-account associations—all from within the Unified Studio interface. Previously, these domain management features were only available for IAM-based domains.

How It Works

  • Domain Management Portal Access: Administrators log into their SageMaker Unified Studio IDC-based domain and navigate to the "Domain management" section in the left navigation pane, which is restricted to users with the Administrator designation.
  • Project Management: From the domain administration page, administrators can create new projects and manage existing ones, including viewing project details, editing project configuration, and deleting projects.
  • Configurable Execution Roles: Each project can be assigned a configurable execution role that defines which AWS analytics, AI, and ML services the project is permitted to access, enabling fine-grained service-level access control.
  • Unified VPC Configuration: Network settings (VPC, subnets, security groups) are configured at the domain level and automatically inherited by all projects within that domain; administrators can edit these settings and changes propagate consistently across both IAM and IDC domain types.
  • User and Permission Management: Administrators can manage user access and permissions directly within the portal, including assigning or revoking the Administrator designation.
  • Cross-Account Association Management: Administrators can associate additional AWS accounts with the domain, enabling users to publish and consume data across account boundaries from within Unified Studio.

Why It's Important

  • Eliminates Console Switching: Administrators of IDC-based domains no longer need to leave the Unified Studio portal and navigate the AWS console to perform domain management tasks, reducing operational friction and context switching.
  • Parity Across Authentication Models: Organizations that standardized on AWS IAM Identity Center for workforce identity can now enjoy the same rich domain management experience previously exclusive to IAM-based domains, removing a significant capability gap.
  • Centralized Governance: Consolidating project creation, role configuration, networking, and user management in one portal simplifies governance and audit workflows for data and ML platform teams.
  • Scalable Multi-Account Data Sharing: The cross-account association feature allows enterprises to build hub-and-spoke data architectures where a central Unified Studio domain can federate data access across multiple AWS accounts without custom integrations.
  • Consistent Security Posture: Domain-level VPC inheritance ensures all projects automatically comply with organizational networking policies, reducing the risk of misconfigured network settings at the project level.

How It's Different

  • Before This Launch: Domain management capabilities (project creation, execution role configuration, VPC settings, user management) were only available for IAM-based domains within Unified Studio; IDC-based domain admins had to rely on the AWS console.
  • Now Unified Across Domain Types: Both IAM-based and IDC-based domains share the same domain management experience inside the Unified Studio portal, creating a consistent administrative workflow regardless of the identity provider chosen.
  • IDC-Specific Advantage: IDC-based domains leverage AWS IAM Identity Center for workforce identity federation, making this update particularly valuable for enterprises using SSO/SAML-based identity providers who previously lacked in-portal management.
  • VPC Consistency Model: Unlike project-level networking configurations that can diverge, the new model enforces domain-level VPC settings inherited by all projects, which is a stronger consistency guarantee than many competing ML platform approaches.
  • Cross-Account Scope: The associated accounts feature goes beyond single-account data management, enabling multi-account data mesh patterns natively within the Unified Studio UI rather than requiring separate DataZone or Lake Formation configurations.

When to Prefer It

  • Enterprise SSO Environments: Organizations using AWS IAM Identity Center with SAML/OIDC federation (e.g., Okta, Azure AD, Ping) who want to manage their SageMaker Unified Studio domain without switching to the AWS console.
  • Large Data Platform Teams: Teams with dedicated domain administrators who need a self-service portal to create and configure projects for multiple business units or data domains without requiring AWS console access for every change.
  • Multi-Account Data Architectures: Organizations operating a data mesh or hub-and-spoke model where a central analytics platform needs to publish and consume data across multiple AWS accounts.
  • Strict Network Compliance Requirements: Enterprises with mandatory VPC, subnet, and security group policies who need to enforce consistent networking across all ML/analytics projects without relying on per-project configuration.
  • Separation of Duties: Scenarios where platform administrators should manage domain-level settings (networking, accounts, roles) while data scientists and analysts work within projects—this portal enforces that boundary cleanly.
  • Migrating from IAM to IDC Domains: Teams transitioning their identity model from IAM-based to IDC-based domains who want to ensure no loss of administrative capability during or after the migration.

Availability

  • GA Status: Generally Available as of May 22, 2026.
  • Supported Regions: Available in all 15 regions where Amazon SageMaker Unified Studio is supported: US East (N. Virginia), US East (Ohio), US West (Oregon), Europe (Ireland), Europe (Frankfurt), Europe (London), Europe (Paris), Europe (Stockholm), Asia Pacific (Tokyo), Asia Pacific (Seoul), Asia Pacific (Singapore), Asia Pacific (Sydney), Asia Pacific (Mumbai), South America (São Paulo), and Canada (Central).
  • Pricing: No separate charge for domain management features; standard SageMaker Unified Studio and underlying service pricing applies.
  • Prerequisites: The IAM role used to create the domain is automatically granted Administrator designation; additional users must be explicitly designated as Administrators to access the domain management portal.
  • Limitation: Access to the domain administration page is restricted to users with the Administrator designation—standard project users cannot access domain-level management functions.

Tags

Servicessagemakersagemaker-unified-studio
Typenew-featurega-launch
Conceptsmlops
Use Casesenterprise
GeographyGlobal

Related Resources

AI Radar AWS

AWS AI/ML news — curated, researched, explained

An automated intelligence platform that curates, researches, and analyzes AWS AI/ML/GenAI announcements daily. Every report is backed by real research — the system reads linked blog posts and documentation to provide accurate, in-depth analysis.

How Each Report Is Generated

  1. Collection — Daily monitoring of the AWS "What's New" RSS feed
  2. Filtering — AI-powered relevance detection for AI/ML/GenAI topics
  3. Taxonomy Tagging — LLM-based classification across 6 dimensions
  4. Importance Scoring — Point-based system with tag bonuses (1-5 stars)
  5. Research Phase — Follows links to blog posts and documentation
  6. Report Generation — Claude Sonnet produces structured 6-section analysis
  7. Visual Summary — Claude Opus generates Mermaid diagrams for key items
  8. Publishing — Static website rebuilt and deployed via CloudFront

Features

  • Faceted filtering by service, type, concept, and more
  • Multi-dimensional taxonomy with 80+ tags across 6 dimensions
  • Geographic availability badges (Global, APJ, EMEA, AMER) with filtering
  • Timeline visualization of announcement volume
  • PDF export for offline reading
  • Mermaid visual summaries for key announcements
  • Daily automated updates — no manual curation
What makes this different: Each report involves a dedicated research phase where the system reads linked blog posts and AWS documentation pages. This produces analysis that goes beyond the original announcement text.

Technology

Built with Python, AWS Lambda, Amazon Bedrock (Claude Sonnet 4.6, Opus 4.6, Haiku 4.5), S3, CloudFront, WAF, EventBridge, and CDK.

Open Source

This project is open source. Fork it, customize it for your needs, and deploy your own instance.
📦 github.com/bbonik/ai-radar-aws

How Importance Scoring Works

Each announcement receives a point score based on multiple factors. The total score maps to a 1-5 star rating:

1★ < 2 pts 2★ ≥ 2 pts 3★ ≥ 3.5 pts 4★ ≥ 5 pts 5★ ≥ 6.5 pts

Point Breakdown

FactorPointsWhen
Core AI service (Bedrock, AgentCore, SageMaker AI)+4Service named in title
Key AI service (SageMaker, Kiro, QuickSight)+2Service named in title
Other AI-related service+1Default
Blog post link+3Link to aws.amazon.com/blogs/
GitHub samples link+2Link to github.com/aws*
Documentation link+1Link to docs.aws.amazon.com/
New model+1.5Tagged as "new-model"
New service+1Tagged as "new-service"
New feature+0.5Tagged as "new-feature"
Anthropic / OpenAI provider+2Provider explicitly mentioned
Instance / notebook announcement-2Hardware/capacity, not feature
Performance / pricing / security-0.5Incremental updates
Region expansion to APJ+1Expands to Asia Pacific
Region expansion (non-APJ only)-1.5Only expands to other regions

Geographic Relevance Badges

Each announcement card shows a small badge indicating whether the feature is available in your region:

🌐 Global Available in all regions
🌏 APJ Asia Pacific
🌍 EMEA Europe / Middle East / Africa
🌎 AMER Americas (US, Canada, South America)
No badge Geography unknown
How geography is detected: The system detects ALL geographies mentioned in each announcement. If the text mentions specific regions (Tokyo, Frankfurt, Oregon, etc.), the corresponding geography badges are shown. If it says "all regions" or is a new feature with no region specified, it gets the Global badge. Geography is also filterable — click a geo chip to see only announcements available in that region.