Publicado el Deja un comentario

Amazon Cognito now supports passwordless authentication for low-friction and secure logins in the AWS GovCloud (US) Regions

Today, Amazon Cognito announced support for passwordless authentication for low-friction and secure logins in the AWS GovCloud (US) Regions. Amazon Cognito now allows you to secure user access to your applications with passwordless authentication, including sign-in with passkeys, email, and text message. Passkeys are based on FIDO standards and use public key cryptography, which enables strong, phishing-resistant authentication. With passwordless authentication, you can reduce the friction associated with traditional password-based authentication and thus simplify the user log-in experience for their applications. For example, if your users choose to use passkeys to log in, they can do so using a built-in authenticator, such as Touch ID on Apple MacBooks and Windows Hello facial recognition on PCs.

Amazon Cognito provides millions of users with secure, scalable, and customizable sign-up and sign-in experiences within minutes. With this launch, AWS is now extending the support for passwordless authentication to the applications you build. This enables your end-users to log in to your applications with a low-friction and secure approach.

Passwordless authentication is offered as part of the Cognito Essentials tier and can be used in all AWS Regions where Amazon Cognito is available, including AWS GovCloud (US). To get started, see the following resources:

 

​Today, Amazon Cognito announced support for passwordless authentication for low-friction and secure logins in the AWS GovCloud (US) Regions. Amazon Cognito now allows you to secure user access to your applications with passwordless authentication, including sign-in with passkeys, email, and text message. Passkeys are based on FIDO standards and use public key cryptography, which enables strong, phishing-resistant authentication. With passwordless authentication, you can reduce the friction associated with traditional password-based authentication and thus simplify the user log-in experience for their applications. For example, if your users choose to use passkeys to log in, they can do so using a built-in authenticator, such as Touch ID on Apple MacBooks and Windows Hello facial recognition on PCs. Amazon Cognito provides millions of users with secure, scalable, and customizable sign-up and sign-in experiences within minutes. With this launch, AWS is now extending the support for passwordless authentication to the applications you build. This enables your end-users to log in to your applications with a low-friction and secure approach. Passwordless authentication is offered as part of the Cognito Essentials tier and can be used in all AWS Regions where Amazon Cognito is available, including AWS GovCloud (US). To get started, see the following resources:

Pricing Detail Page
AWS News Blog
Developer Guide  

Publicado el Deja un comentario

Amazon Bedrock now supports multi-agent collaboration

Today, AWS announces the general availability (GA) of multi-agent collaboration for Amazon Bedrock, allowing developers to create networks of specialized agents that communicate and coordinate under the guidance of a supervisor agent. This new capability allows you to tackle more intricate, multi-step workflows and scale your AI-driven applications more effectively.

Amazon Bedrock multi-agent collaboration GA introduces key enhancements designed to improve scalability, flexibility, and operational efficiency. Inline Agents allow you to dynamically adjust agent roles and behaviors at runtime, making workflows more adaptable as your business needs evolve. With Payload Referencing, supervisor agents can reference linked data instead of embedding it in every request, reducing data transfer, improving response times, and lowering operational costs. Additionally, multi-agent now offers CloudFormation (CFN) and Cloud Development Kit (CDK) support so you can create reusable teams of agents as templates that can be shared across accounts within an organization.

This release also introduces agent monitoring and observability features, helping you track, monitor, and optimize agent interactions more efficiently. These features improve debugging and traceability, ensuring better visibility into agent workflows and making troubleshooting easier for developers.

Multi-agent collaboration on Amazon Bedrock is now available in all AWS Regions where Amazon Bedrock is supported. To learn more about this feature and how it can help you build more sophisticated AI applications, see the Amazon Bedrock product page or refer to the documentation for detailed information on getting started.

 

​Today, AWS announces the general availability (GA) of multi-agent collaboration for Amazon Bedrock, allowing developers to create networks of specialized agents that communicate and coordinate under the guidance of a supervisor agent. This new capability allows you to tackle more intricate, multi-step workflows and scale your AI-driven applications more effectively.
Amazon Bedrock multi-agent collaboration GA introduces key enhancements designed to improve scalability, flexibility, and operational efficiency. Inline Agents allow you to dynamically adjust agent roles and behaviors at runtime, making workflows more adaptable as your business needs evolve. With Payload Referencing, supervisor agents can reference linked data instead of embedding it in every request, reducing data transfer, improving response times, and lowering operational costs. Additionally, multi-agent now offers CloudFormation (CFN) and Cloud Development Kit (CDK) support so you can create reusable teams of agents as templates that can be shared across accounts within an organization.
This release also introduces agent monitoring and observability features, helping you track, monitor, and optimize agent interactions more efficiently. These features improve debugging and traceability, ensuring better visibility into agent workflows and making troubleshooting easier for developers.
Multi-agent collaboration on Amazon Bedrock is now available in all AWS Regions where Amazon Bedrock is supported. To learn more about this feature and how it can help you build more sophisticated AI applications, see the Amazon Bedrock product page or refer to the documentation for detailed information on getting started.  

Publicado el Deja un comentario

Replantear la seguridad de la asistencia remota en un mundo Zero Trust

marzo 10, 2025

Replantear la seguridad de la asistencia remota en un mundo Zero Trust

Por: Talal Alqinawi, director sénior de marketing de productos de Intune.

La reciente brecha de seguridad del Tesoro de los Estados Unidos subraya una cruda realidad: los adversarios cibernéticos ya no solo buscan brechas en la seguridad de la red tradicional, sino que explotan de manera activa las herramientas en las que confían las organizaciones para las operaciones diarias. Las tecnologías de asistencia remota, esenciales para el soporte de TI y la continuidad del negocio, se han convertido en objetivos principales para el robo de credenciales, el movimiento dentro de la red y la explotación del sistema. El mensaje es claro: asegurar la asistencia remota ya no es opcional; es un requisito fundamental para mantener la resiliencia operativa.  

Un enfoque múltiple para proteger la asistencia remota con Zero Trust

Durante demasiado tiempo, la seguridad de la asistencia remota se ha asumido en lugar de diseñarse intencionalmente en su arquitectura. El aumento de las ciberamenazas sofisticadas exige un cambio fundamental en nuestro enfoque. Las organizaciones deben replantearse la seguridad de la asistencia remota a través de la lente de Zero Trust, por medio de los tres principios clave de verificación explícita, uso de privilegios mínimos y asumir la violación como guía y garantizar que cada sesión, usuario y dispositivo se verifique, cumpla y supervise antes de conceder el acceso.

Descubran cómo la implementación de Zero Trust puede fortalecer la seguridad de su asistencia remota al visitar nuestro Taller de Zero Trust, donde encontrarán una guía interactiva para integrar la seguridad en sus operaciones de TI.  

Esto requiere un enfoque estructurado con una base de:

  1. Control de identidad y acceso: garantiza que solo los usuarios y dispositivos autenticados y conformes puedan iniciar o recibir asistencia remota.
  2. Seguridad y cumplimiento de endpoints: aplicación de líneas de base de seguridad y acceso condicional en todos los dispositivos administrados.
  3. Seguridad integrada en la asistencia remota: incorporar la seguridad en la base misma de las herramientas de asistencia remota, para eliminar las brechas que los ciberatacantes pueden explotar.

Control de identidad y acceso: la primera línea de defensa de la ciberseguridad

La seguridad de la identidad es la piedra angular de cualquier estrategia de asistencia remota segura. Una identidad comprometida suele ser el primer paso de un ciberataque, por lo que es fundamental garantizar que solo los usuarios y dispositivos verificados puedan iniciar o recibir sesiones de asistencia remota. Las organizaciones deben hacer cumplir lo siguiente:

  • Verificación de identidad explícita: mediante la autenticación multifactor (MFA, por sus siglas en inglés) y el acceso condicional basado en riesgos para garantizar que solo los usuarios autorizados obtengan acceso.
  • Acceso con privilegios mínimos: garantizar que la asistencia remota se otorgue solo durante el tiempo necesario y con privilegios mínimos para reducir el riesgo de explotación.
  • Evaluación de riesgos en tiempo real: evaluación continua de las solicitudes de acceso en busca de anomalías o actividades sospechosas para evitar el acceso no autorizado.

Al cambiar el perímetro de seguridad a la identidad, las organizaciones crean un entorno en el que la confianza se gana de forma dinámica, no se asume.

Cierre de brechas con la seguridad de los puntos de conexión y el cumplimiento con Microsoft Intune

Con frecuencia, los ciberatacantes explotan puntos finales (endpoints) obsoletos, mal configurados o que no cumplen con las normas para afianzarse en los entornos empresariales. Los líderes de TI y seguridad deben asegurarse de que la asistencia remota se base en una sólida base de seguridad de endpoints, donde cada dispositivo que se conecta a los recursos corporativos cumple con estrictos estándares de cumplimiento. Esto pone de manifiesto la necesidad de que las organizaciones establezcan políticas de seguridad coherentes en todos los dispositivos, asegurándose de que estén actualizadas y cumplan antes de que se les conceda el acceso remoto.

Microsoft Intune proporciona las herramientas necesarias para:

  • Aplicar políticas de cumplimiento: restrinjan la asistencia remota a dispositivos administrados, actualizados y que cumplan con las políticas.
  • Aplicar líneas de base de seguridad: estandaricen las configuraciones en todos los endpoints para minimizar las brechas de seguridad.
  • Integración con el ecosistema de seguridad de Microsoft, para conectar los flujos de trabajo de asistencia remota con Microsoft Entra, la familia de productos Microsoft Defender y otras herramientas de seguridad para la supervisión en tiempo real y la mitigación de amenazas cibernéticas.  

Más información sobre Microsoft Intune

Ayuda remota: asistencia remota segura creada para Zero Trust

A medida que las organizaciones trabajan hacia un modelo Zero Trust, la asistencia remota segura debe alinearse con los principios básicos de seguridad. Esto significa ir más allá de las medidas de seguridad reactivas e incorporar controles proactivos basados en políticas en cada sesión remota. La Ayuda remota de Microsoft Intune se diseñó con estos imperativos en mente, para brindar una solución sólida que mejora el soporte de TI y minimiza los riesgos de seguridad.

Si bien las herramientas de asistencia remota heredadas pueden carecer de controles de seguridad de nivel empresarial, Remote Help está diseñada para alinearse con los principios de Zero Trust. A diferencia de las soluciones tradicionales, la ayuda remota:

  • Se integra directo con Microsoft Entra ID, lo que mejora la seguridad donde la autenticación y los controles de acceso pueden tener lugar de forma coherente.
  • Proporciona transparencia en las sesiones: los equipos de TI pueden rastrear y monitorear la actividad de asistencia remota en tiempo real.
  • Aplica los requisitos de cumplimiento: solo los dispositivos administrados y que cumplen con las normas pueden participar en las sesiones de asistencia remota.  

Para los sectores con una alta regulación, la Ayuda Remota ofrece una alternativa a las herramientas de terceros que pueden introducir puntos ciegos de seguridad. Al integrar la seguridad directo en los flujos de trabajo de asistencia remota, las organizaciones pueden reducir de manera significativa el riesgo de acceso no autorizado.

Iniciar una prueba gratuita de la Ayuda Remota de Microsoft Intune

Involucrar a clientes y socios para fortalecer la resiliencia cibernética

La ciberseguridad es un deporte de equipo. A medida que los actores de amenazas cibernéticas se vuelven más sofisticados, la colaboración entre industrias es esencial. Microsoft se compromete a interactuar con clientes y socios para impulsar la seguridad, la innovación y la resistencia. Iniciativas como la Iniciativa de Resiliencia de Windows (WRI, por sus siglas en inglés) se centran en:

  • Reducir la necesidad de privilegios de administrador: ayudar a las organizaciones a adoptar un enfoque de privilegios mínimos a escala.
  • Mejorar la protección de la identidad: fortalecimiento de las defensas contra el phishing y los ataques basados en la identidad.
  • Recuperar máquinas de manera rápida: dota a los equipos de TI de herramientas para almacenar con rapidez dispositivos comprometidos de forma remota.

Al fomentar la colaboración y las medidas de seguridad en constante evolución, Microsoft ayuda a las organizaciones a mantenerse a la vanguardia de las ciberamenazas emergentes. Estas conversaciones continuas con nuestros clientes y socios son cruciales para dar forma a estrategias de seguridad resilientes que se adapten a un panorama de amenazas cibernéticas en constante cambio.

Un enfoque que prioriza la seguridad para el futuro

La creciente dependencia de la asistencia remota exige una mentalidad que priorice la seguridad. Las organizaciones deben reconocer que cada sesión de acceso remoto presenta una oportunidad para la explotación por parte de un elenco de ciberatacantes en constante evolución. En lugar de tratar la seguridad como una idea tardía, debe integrarse a profundidad en la arquitectura de las soluciones de asistencia remota. Un enfoque moderno requiere mitigación proactiva de riesgos, verificación continua y controles de seguridad sin interrupciones que respalden la productividad sin comprometer la protección.

Ahora es el momento de que los líderes de TI y seguridad:

  • Evalúen sus herramientas de asistencia remota actuales, para identificar las brechas y las áreas de mejora.
  • Adopten los principios de Zero Trust, para garantizar que el acceso se verifique y se supervise de forma explícita y continua.
  • Aprovechen soluciones como Microsoft Intune y Remote Help, para implementar capacidades de asistencia remota seguras y de nivel empresarial.

Al seguir estos pasos, pueden fortalecer su postura de seguridad, minimizar el riesgo y garantizar que la asistencia remota siga como una herramienta para la eficiencia operativa en lugar de una puerta de entrada para las amenazas cibernéticas.

Para explorar cómo Zero Trust puede mejorar la seguridad de su asistencia remota, visiten el Taller de Zero Trust, una guía interactiva paso a paso para integrar la seguridad en cada capa de las operaciones de TI, lo que garantiza un enfoque integral y medible para la transformación de la seguridad.

Exploren el taller de Zero Trust

Conozcan más de Microsoft Security

Para obtener más información sobre las soluciones de seguridad de Microsoft, visiten nuestro sitio web. Agreguen a Favoritos el blog de Seguridad para mantenerse al día con nuestra cobertura experta en asuntos de seguridad. Además, síganos en LinkedIn (Microsoft Security) y X (@MSFTSecurity) para conocer las últimas noticias y actualizaciones sobre ciberseguridad. 

The post Replantear la seguridad de la asistencia remota en un mundo Zero Trust appeared first on Source LATAM.

 

​The post Replantear la seguridad de la asistencia remota en un mundo Zero Trust appeared first on Source LATAM.  

Publicado el Deja un comentario

Amazon Athena Provisioned Capacity now available in the Asia Pacific (Mumbai) Region

Amazon Athena Provisioned Capacity is now available in the Asia Pacific (Mumbai) Region. Provisioned Capacity allows you to run SQL queries on dedicated serverless resources for a fixed price, with no long-term commitment, and control workload performance characteristics such as query concurrency and cost.

Athena is a serverless, interactive query service that makes it possible to analyze petabyte-scale data with ease and flexibility. Provisioned Capacity provides workload management capabilities that help you prioritize, isolate, and scale your workloads. For example, use Provisioned Capacity when you need to run a high number of queries at the same time or isolate important queries from other queries that run in the same account. To get started, use the Athena console, AWS SDK, or CLI to request capacity and then select workgroups with queries you want to run on dedicated capacity.

For more information on AWS Regions where Provisioned Capacity is available, see Manage query processing capacity.

To learn more, visit Manage query processing capacity in the Amazon Athena User Guide and the Athena pricing page.

 

​Amazon Athena Provisioned Capacity is now available in the Asia Pacific (Mumbai) Region. Provisioned Capacity allows you to run SQL queries on dedicated serverless resources for a fixed price, with no long-term commitment, and control workload performance characteristics such as query concurrency and cost. Athena is a serverless, interactive query service that makes it possible to analyze petabyte-scale data with ease and flexibility. Provisioned Capacity provides workload management capabilities that help you prioritize, isolate, and scale your workloads. For example, use Provisioned Capacity when you need to run a high number of queries at the same time or isolate important queries from other queries that run in the same account. To get started, use the Athena console, AWS SDK, or CLI to request capacity and then select workgroups with queries you want to run on dedicated capacity. For more information on AWS Regions where Provisioned Capacity is available, see Manage query processing capacity. To learn more, visit Manage query processing capacity in the Amazon Athena User Guide and the Athena pricing page.  

Publicado el Deja un comentario

AWS HealthOmics workflows now support NVIDIA L4 and L40S GPUs and expanded CPU options

AWS HealthOmics now supports the latest NVIDIA L4 and L40S graphical processing units (GPUs) and larger compute options of up to 192 vCPUs for workflows. AWS HealthOmics is a HIPAA-eligible service that helps healthcare and life sciences customers accelerate scientific breakthroughs with fully managed biological data stores and workflows. This release expands workflow compute capabilities to support more demanding workloads for genomics research and analysis.

In addition to current support for NVIDIA A10G and T4 GPUs, this release adds support for NVIDIA L4 and L40S GPUs, which enables researchers to efficiently run complex machine learning workloads such as protein structure prediction and biological foundation models (bioFMs). The enhanced CPU configurations with up to 192 vCPUs and 1,536 GiB of memory allows for faster processing of large-scale genomics datasets. These improvements help research teams reduce time-to-insight for critical life sciences work.

NVIDIA L4 and L40S GPUs and 128 and 192 vCPU omics instance types are now available in: US East (N. Virginia) and US West (Oregon). To get started with AWS HealthOmics workflows, see the documentation.
 

 

​AWS HealthOmics now supports the latest NVIDIA L4 and L40S graphical processing units (GPUs) and larger compute options of up to 192 vCPUs for workflows. AWS HealthOmics is a HIPAA-eligible service that helps healthcare and life sciences customers accelerate scientific breakthroughs with fully managed biological data stores and workflows. This release expands workflow compute capabilities to support more demanding workloads for genomics research and analysis. In addition to current support for NVIDIA A10G and T4 GPUs, this release adds support for NVIDIA L4 and L40S GPUs, which enables researchers to efficiently run complex machine learning workloads such as protein structure prediction and biological foundation models (bioFMs). The enhanced CPU configurations with up to 192 vCPUs and 1,536 GiB of memory allows for faster processing of large-scale genomics datasets. These improvements help research teams reduce time-to-insight for critical life sciences work. NVIDIA L4 and L40S GPUs and 128 and 192 vCPU omics instance types are now available in: US East (N. Virginia) and US West (Oregon). To get started with AWS HealthOmics workflows, see the documentation.    

Publicado el Deja un comentario

Amazon Redshift Data API now supports single sign-on (SSO) with AWS IAM Identity Center

Amazon Redshift Data API, which lets you connect to Amazon Redshift through a secure HTTPS endpoint, now supports single sign-on (SSO) through AWS IAM Identity Center. Amazon Redshift Data API removes the need to manage database drivers, connections, network configurations, and data buffering, simplifying how you access your data warehouses and data lakes.

AWS IAM Identity Center lets customers connect existing identity providers from a centrally managed location. You can now use AWS IAM Identity Center with your preferred identity provider, including Microsoft Entra Id, Okta, and Ping, to connect to Amazon Redshift clusters through Amazon Redshift Data API. This new SSO integration simplifies identity management, so that you don’t have to manage separate database credentials for your Amazon Redshift clusters. Once authenticated, your authorization rules are enforced using the permissions defined in Amazon Redshift or AWS Lake Formation.

You can get started by integrating your Amazon Redshift cluster or workgroup with AWS Identity Center (IdC), and then allow Amazon Redshift to access AWS services programmatically using trusted identity propagation.

This feature is available in all AWS Regions where both AWS IAM Identity Center and Amazon Redshift are available. For more information, see our documentation and blog.
 

 

​Amazon Redshift Data API, which lets you connect to Amazon Redshift through a secure HTTPS endpoint, now supports single sign-on (SSO) through AWS IAM Identity Center. Amazon Redshift Data API removes the need to manage database drivers, connections, network configurations, and data buffering, simplifying how you access your data warehouses and data lakes. AWS IAM Identity Center lets customers connect existing identity providers from a centrally managed location. You can now use AWS IAM Identity Center with your preferred identity provider, including Microsoft Entra Id, Okta, and Ping, to connect to Amazon Redshift clusters through Amazon Redshift Data API. This new SSO integration simplifies identity management, so that you don’t have to manage separate database credentials for your Amazon Redshift clusters. Once authenticated, your authorization rules are enforced using the permissions defined in Amazon Redshift or AWS Lake Formation. You can get started by integrating your Amazon Redshift cluster or workgroup with AWS Identity Center (IdC), and then allow Amazon Redshift to access AWS services programmatically using trusted identity propagation. This feature is available in all AWS Regions where both AWS IAM Identity Center and Amazon Redshift are available. For more information, see our documentation and blog.    

Publicado el Deja un comentario

Application Load Balancer announces integration with Amazon VPC IPAM

AWS Application Load Balancer (ALB) now allows customers to provide a pool of public IPv4 addresses for IP address assignment to load balancer nodes. Customers can configure a public IP Address Manager (IPAM) pool that can consist of either Bring Your Own IP addresses (BYOIPs) that is customer owned or a contiguous IPv4 address block provided by Amazon.

With this feature, customers can optimize public IPv4 cost by using BYOIP in public IPAM pools. Customers can also simplify their enterprise allowlisting and operations, by using Amazon-provided contiguous IPv4 blocks in public IPAM pools. The ALB’s IP addresses are sourced from the IPAM pool and automatically switch to AWS managed IP addresses when the public IPAM pool is depleted. This intelligent switching maximizes service availability during scaling events.

The feature is available in all commercial AWS Regions and AWS GovCloud (US) Regions where Amazon VPC IP Address Manager (IPAM) is available. To learn more, please refer to the ALB Documentation.
 

 

​AWS Application Load Balancer (ALB) now allows customers to provide a pool of public IPv4 addresses for IP address assignment to load balancer nodes. Customers can configure a public IP Address Manager (IPAM) pool that can consist of either Bring Your Own IP addresses (BYOIPs) that is customer owned or a contiguous IPv4 address block provided by Amazon. With this feature, customers can optimize public IPv4 cost by using BYOIP in public IPAM pools. Customers can also simplify their enterprise allowlisting and operations, by using Amazon-provided contiguous IPv4 blocks in public IPAM pools. The ALB’s IP addresses are sourced from the IPAM pool and automatically switch to AWS managed IP addresses when the public IPAM pool is depleted. This intelligent switching maximizes service availability during scaling events. The feature is available in all commercial AWS Regions and AWS GovCloud (US) Regions where Amazon VPC IP Address Manager (IPAM) is available. To learn more, please refer to the ALB Documentation.    

Publicado el Deja un comentario

Amazon Connect Contact Lens can now dynamically update the questions on an evaluation form

Contact Lens now enables you to create dynamic evaluation forms that automatically show or hide questions based on responses to previous questions, tailoring each evaluation to specific customer interaction scenarios. For example, when a manager answers “Yes” to the form question «Did the customer try to make a purchase on the call?», the form automatically presents a follow-up question: «Did the agent read the sales disclosure?». With this launch, you can consolidate evaluation forms that are applicable to different interaction scenarios into a single dynamic evaluation form which automatically hides irrelevant questions. This reduces manager effort in selecting the relevant evaluation form and determining which evaluation questions are applicable to the interaction, helping managers perform evaluations faster and more accurately.

This feature is available in all regions where Contact Lens performance evaluations are already available. To learn more, please visit our documentation and our webpage. For information about Contact Lens pricing, please visit our pricing page.
 

 

​Contact Lens now enables you to create dynamic evaluation forms that automatically show or hide questions based on responses to previous questions, tailoring each evaluation to specific customer interaction scenarios. For example, when a manager answers “Yes” to the form question «Did the customer try to make a purchase on the call?», the form automatically presents a follow-up question: «Did the agent read the sales disclosure?». With this launch, you can consolidate evaluation forms that are applicable to different interaction scenarios into a single dynamic evaluation form which automatically hides irrelevant questions. This reduces manager effort in selecting the relevant evaluation form and determining which evaluation questions are applicable to the interaction, helping managers perform evaluations faster and more accurately. This feature is available in all regions where Contact Lens performance evaluations are already available. To learn more, please visit our documentation and our webpage. For information about Contact Lens pricing, please visit our pricing page.    

Publicado el Deja un comentario

Amazon WorkSpaces Pools now supports FIPS 140-2 validated endpoints

Amazon WorkSpaces Pools now offers Federal Information Processing Standard 140-2 (FIPS) validated endpoints (FIPS endpoints) for user streaming sessions. FIPS 140-2 is a U.S. government standard that specifies the security requirements for cryptographic modules that protect sensitive information. WorkSpaces Pools FIPS endpoints use FIPS-validated cryptographic standards, which may be required for certain sensitive information or regulated workloads.

To enable FIPS endpoint encryption for end user streaming via AWS Console, navigate to Directories, and verify that the Pools directory where you want to add FIPS is in a STOPPED state, and that the preferred protocol is set to TCP. Once verified, select the directory and on the Directory Details page update the endpoint encryption to FIPS 140-2 Validated Mode and save.

FIPS support is available for WorkSpaces Pools in 4 AWS regions: AWS GovCloud (US-East); AWS GovCloud (US-West); US East (N. Virginia); and US West (Oregon). For more information about using FIPS endpoints in WorkSpaces Pools, see Configure FedRAMP authorization or DoD SRG validated for WorkSpaces Pools. For more information about how AWS supports FIPS, including a list of WorkSpaces Pools endpoints, see Federal Information Processing Standard (FIPS) 140-2.

 

​Amazon WorkSpaces Pools now offers Federal Information Processing Standard 140-2 (FIPS) validated endpoints (FIPS endpoints) for user streaming sessions. FIPS 140-2 is a U.S. government standard that specifies the security requirements for cryptographic modules that protect sensitive information. WorkSpaces Pools FIPS endpoints use FIPS-validated cryptographic standards, which may be required for certain sensitive information or regulated workloads. To enable FIPS endpoint encryption for end user streaming via AWS Console, navigate to Directories, and verify that the Pools directory where you want to add FIPS is in a STOPPED state, and that the preferred protocol is set to TCP. Once verified, select the directory and on the Directory Details page update the endpoint encryption to FIPS 140-2 Validated Mode and save. FIPS support is available for WorkSpaces Pools in 4 AWS regions: AWS GovCloud (US-East); AWS GovCloud (US-West); US East (N. Virginia); and US West (Oregon). For more information about using FIPS endpoints in WorkSpaces Pools, see Configure FedRAMP authorization or DoD SRG validated for WorkSpaces Pools. For more information about how AWS supports FIPS, including a list of WorkSpaces Pools endpoints, see Federal Information Processing Standard (FIPS) 140-2.  

Publicado el Deja un comentario

Amazon Bedrock Knowledge Bases supports GraphRAG now generally available

Today, AWS announces the general availability of GraphRAG, a capability in Amazon Bedrock Knowledge Bases that enhances Retrieval-Augmented Generation (RAG) by incorporating graph data. GraphRAG delivers more comprehensive, relevant, and explainable responses by leveraging relationships within your data, improving how Generative AI applications retrieve and synthesize information.

Since public preview, customers have leveraged the managed GraphRAG capability to get improved responses to queries from their end users. GraphRAG automatically generates and stores vector embeddings in Amazon Neptune Analytics, along with a graph representation of entities and their relationships. GraphRAG combines vector similarity search with graph traversal, enabling higher accuracy when retrieving information from disparate yet interconnected data sources.

GraphRAG with Amazon Neptune is built right into Amazon Bedrock Knowledge Bases, offering an integrated experience with no additional setup or additional charges beyond the underlying services. GraphRAG is generally available in AWS Regions where Amazon Bedrock Knowledge Bases and Amazon Neptune Analytics are both available (see current list of supported regions). To learn more, visit the Amazon Bedrock User Guide.

 

​Today, AWS announces the general availability of GraphRAG, a capability in Amazon Bedrock Knowledge Bases that enhances Retrieval-Augmented Generation (RAG) by incorporating graph data. GraphRAG delivers more comprehensive, relevant, and explainable responses by leveraging relationships within your data, improving how Generative AI applications retrieve and synthesize information. Since public preview, customers have leveraged the managed GraphRAG capability to get improved responses to queries from their end users. GraphRAG automatically generates and stores vector embeddings in Amazon Neptune Analytics, along with a graph representation of entities and their relationships. GraphRAG combines vector similarity search with graph traversal, enabling higher accuracy when retrieving information from disparate yet interconnected data sources. GraphRAG with Amazon Neptune is built right into Amazon Bedrock Knowledge Bases, offering an integrated experience with no additional setup or additional charges beyond the underlying services. GraphRAG is generally available in AWS Regions where Amazon Bedrock Knowledge Bases and Amazon Neptune Analytics are both available (see current list of supported regions). To learn more, visit the Amazon Bedrock User Guide.