New AWS Sign-Up Sandbox Leaves Security Gaps, Research Finds
AWS has rolled out a new sign-up experience designed to make it easier for newcomers to get started with cloud services. Instead of creating a single account, the process sets up three linked AWS accounts inside an organisation structure: one you can access, and two hidden accounts (an admin/management account and an identity account) that AWS uses behind the scenes to apply restrictions and controls.
Wiz Research examined this new setup and found it works differently to AWS's more security-focused onboarding tool, Control Tower. Notably, the sandbox does not have CloudTrail logging configured at the account or organisation level, meaning detailed activity logs are not automatically captured. Limited event history is available for 90 days through a restricted interface, but this is not the same as full logging. Additionally, S3 Public Block Access, a setting that helps prevent accidental exposure of storage buckets to the internet, is not enabled by default at the account level, though it is switched on for individual new buckets.
Users who outgrow the sandbox environment (for example, by hitting budget or service restrictions) can 'upgrade' their account, gaining visibility into the previously hidden management account and the ability to review what was configured. Until that point, however, businesses using this streamlined sign-up path may be operating with less visibility and fewer default protections than they might expect.