Amazon Web Services Support authorization
Amazon Web Services Support authorization gives you auditable control over Amazon Web Services Support access to information about your services that might contain your data during support case resolution.
A support permit is a customer-managed resource that defines the scope and conditions of authorized access. Each support permit is cryptographically signed by using a customer-managed Amazon Key Management Service (Amazon KMS) key that you control. Amazon CloudTrail logs all actions taken on your resources under your authorization during the granted access period, giving you a complete audit trail.
Important
The information obtained through Amazon Web Services Support authorization might be accessed from outside the Amazon Region where your data is stored.
Amazon Web Services Support authorization supports two authorization scenarios to fit your operational needs.
- Proactive authorization
-
You create support permits in advance to pre-authorize access within a defined scope. When Amazon Web Services Support needs access to resolve an issue, a signed authorization is automatically issued if a matching support permit exists. This reduces resolution time during incidents.
- Reactive authorization
-
Amazon Web Services Support submits a support permit request in the Amazon Web Services Support Center when access to information about your services is needed. You review the request and either approve it by creating a scoped support permit or reject it. If you don't approve the request, Amazon Web Services Support can't access the requested information. This gives you per-case control over access decisions.