← Back to all announcements
★★★☆☆ 07/05/2026

Amazon SageMaker Unified Studio adds identity and user management features

Simplify user access control and SSO setup while maintaining security across your ML teams with unified administration.

View original announcement →

Visual Summary

graph TD A{{SageMaker Unified Studio Identity Management}}:::announced B((Administrators)):::external C((Federated Users)):::external D(AWS IAM Identity Center):::compute E([SSO Configuration]):::feature F([Domain User Management]):::feature G([Per-User Session Isolation]):::feature H(AWS CloudTrail):::compute I([Project Collaboration]):::feature B ==>|"configures"| A A -->|"integrates"| D D -->|"enables"| E A -->|"provides"| F C ==>|"federates via IAM role"| A A -->|"creates"| G G -->|"logs actions"| H A -.->|"supports"| I E -.->|"onboards users"| I classDef announced fill:#ff9900,stroke:#ec7211,color:#fff,font-weight:bold classDef compute fill:#e3f2fd,stroke:#1565c0,color:#1565c0 classDef storage fill:#e8f5e9,stroke:#2e7d32,color:#2e7d32 classDef feature fill:#fff3e0,stroke:#e65100,color:#e65100 classDef external fill:#f5f5f5,stroke:#616161,color:#616161

What's New

Amazon SageMaker Unified Studio has introduced enhanced identity and user management capabilities for both IAM and Identity Center domain types. For IAM domains, administrators can now configure AWS IAM Identity Center to enable SSO onboarding and manage a unified view of all domain users from a single administration page. For Identity Center domains, users can now federate access via IAM roles while maintaining isolated, auditable sessions even when multiple users share the same role.

How It Works

  • In SageMaker IAM domains, administrators configure AWS IAM Identity Center integration through the SageMaker Unified Studio admin portal, after which they can add a mix of IAM roles, IAM users, IAM Identity Center users, and IAM Identity Center groups as project members within the same project.
  • A new domain user management page consolidates all active domain users into a single screen, allowing administrators to adjust access and permissions without navigating multiple consoles.
  • In SageMaker Identity Center domains, federated access via IAM roles is now supported by having SageMaker Unified Studio generate a unique user session per federated principal — meaning that even if two users assume the same IAM role, their sessions are isolated, their work is not overwritten, and their individual actions are independently attributable for audit purposes via AWS CloudTrail or equivalent logging mechanisms.

Why It's Important

  • These features address a common enterprise pain point: organizations rarely use a single, uniform authentication method across all teams and users.
  • By allowing both IAM-native identities and corporate SSO identities (via IAM Identity Center) to coexist within the same SageMaker Unified Studio project, AWS removes a significant collaboration barrier.
  • The per-session isolation for federated IAM role users is particularly important for compliance and security teams, as it enables individual-level auditability even in environments where role sharing is operationally necessary — a requirement in many regulated industries.

How It's Different

  • Previously, SageMaker IAM domains and Identity Center domains operated with more rigid identity boundaries: IAM domains lacked native SSO integration, and Identity Center domains did not support IAM role federation.
  • Mixing identity types within a single project was not straightforward, forcing organizations to either standardize on one authentication method or manage separate domains.
  • The new domain user management page also replaces a fragmented experience where administrators had to cross-reference multiple IAM and Identity Center consoles to get a complete picture of who had access to a domain.
  • The per-session uniqueness for shared IAM roles in Identity Center domains is a new capability that did not previously exist, closing a gap where shared-role users could inadvertently overwrite each other's work.

When to Prefer It

  • These features are most valuable for enterprise organizations that have heterogeneous identity environments — for example, teams where some members authenticate via corporate SSO (Identity Center) and others use programmatic IAM roles or legacy IAM users.
  • Organizations in regulated industries (finance, healthcare, government) that require per-user audit trails but cannot avoid IAM role sharing should specifically leverage the federated session isolation in Identity Center domains.
  • Administrators managing large teams will benefit from the consolidated user management page to reduce operational overhead.
  • If your organization is already standardized on a single identity method and has no cross-authentication collaboration needs, the impact of these features will be more limited.

Availability

  • These features are generally available (GA) as of May 7, 2026.
  • They are supported across 15 AWS regions: Asia Pacific (Mumbai, Seoul, Singapore, Sydney, Tokyo), Canada (Central), Europe (Frankfurt, Ireland, London, Paris, Stockholm), South America (São Paulo), US East (N.
  • Virginia, Ohio), and US West (Oregon).
  • Notable regions not yet listed include AWS GovCloud (US), China regions, and several newer commercial regions, which may be relevant for public sector or data-sovereignty use cases.
  • No preview or beta limitations were indicated in the announcement.

Tags

Servicessagemaker-unified-studio
Typenew-feature
Conceptsmlops
Use Casesenterprise
GeographyAMERICASAPJEMEA

AI Radar AWS

AWS AI/ML news — curated, researched, explained

An automated intelligence platform that curates, researches, and analyzes AWS AI/ML/GenAI announcements daily. Every report is backed by real research — the system reads linked blog posts and documentation to provide accurate, in-depth analysis.

How Each Report Is Generated

  1. Collection — Daily monitoring of the AWS "What's New" RSS feed
  2. Filtering — AI-powered relevance detection for AI/ML/GenAI topics
  3. Taxonomy Tagging — LLM-based classification across 6 dimensions
  4. Importance Scoring — Point-based system with tag bonuses (1-5 stars)
  5. Research Phase — Follows links to blog posts and documentation
  6. Report Generation — Claude Sonnet produces structured 6-section analysis
  7. Visual Summary — Claude Opus generates Mermaid diagrams for key items
  8. Publishing — Static website rebuilt and deployed via CloudFront

Features

  • Faceted filtering by service, type, concept, and more
  • Multi-dimensional taxonomy with 80+ tags across 6 dimensions
  • Geographic availability badges (Global, APJ, EMEA, AMER) with filtering
  • Timeline visualization of announcement volume
  • PDF export for offline reading
  • Mermaid visual summaries for key announcements
  • Daily automated updates — no manual curation
What makes this different: Each report involves a dedicated research phase where the system reads linked blog posts and AWS documentation pages. This produces analysis that goes beyond the original announcement text.

Technology

Built with Python, AWS Lambda, Amazon Bedrock (Claude Sonnet 4.6, Opus 4.6, Haiku 4.5), S3, CloudFront, WAF, EventBridge, and CDK.

Open Source

This project is open source. Fork it, customize it for your needs, and deploy your own instance.
📦 github.com/bbonik/ai-radar-aws

How Importance Scoring Works

Each announcement receives a point score based on multiple factors. The total score maps to a 1-5 star rating:

1★ < 2 pts 2★ ≥ 2 pts 3★ ≥ 3.5 pts 4★ ≥ 5 pts 5★ ≥ 6.5 pts

Point Breakdown

FactorPointsWhen
Core AI service (Bedrock, AgentCore, SageMaker AI)+4Service named in title
Key AI service (SageMaker, Kiro, QuickSight)+2Service named in title
Other AI-related service+1Default
Blog post link+3Link to aws.amazon.com/blogs/
GitHub samples link+2Link to github.com/aws*
Documentation link+1Link to docs.aws.amazon.com/
New model+1.5Tagged as "new-model"
New service+1Tagged as "new-service"
New feature+0.5Tagged as "new-feature"
Anthropic / OpenAI provider+2Provider explicitly mentioned
Instance / notebook announcement-2Hardware/capacity, not feature
Performance / pricing / security-0.5Incremental updates
Region expansion to APJ+1Expands to Asia Pacific
Region expansion (non-APJ only)-1.5Only expands to other regions

Geographic Relevance Badges

Each announcement card shows a small badge indicating whether the feature is available in your region:

🌐 Global Available in all regions
🌏 APJ Asia Pacific
🌍 EMEA Europe / Middle East / Africa
🌎 AMER Americas (US, Canada, South America)
No badge Geography unknown
How geography is detected: The system detects ALL geographies mentioned in each announcement. If the text mentions specific regions (Tokyo, Frankfurt, Oregon, etc.), the corresponding geography badges are shown. If it says "all regions" or is a new feature with no region specified, it gets the Global badge. Geography is also filterable — click a geo chip to see only announcements available in that region.