View a markdown version of this page

Document History - AWS Config

Document History

The following table describes the important changes to the documentation for AWS Config. For notification about updates to this documentation, you can subscribe to an RSS feed.

  • API version: 2014-11-12

  • Latest documentation update: August 13, 2026

ChangeDescriptionDate

Security IAM updates

The AWSConfigServiceRolePolicy and AWS_ConfigRole policies now grant additional permissions for bedrock-agentcore and sagemaker services. For more information, see AWS managed policies for AWS Config.

August 27, 2026

Security IAM updates

The AWSConfigServiceRolePolicy and AWS_ConfigRole policies now grant additional permissions for access-analyzer, bedrock, bedrock-agentcore, notifications, nova-act, s3vectors, and sagemaker services. For more information, see AWS managed policies for AWS Config.

August 1, 2026

New resource types for AWS Config

With this release, you can use AWS Config to record configuration changes to new Amazon API Gateway, Amazon API Gateway V2, Amazon Elastic Compute Cloud (Amazon EC2), AWS Network Firewall, Amazon OpenSearch Ingestion, Amazon S3 Vectors, a capability of Amazon S3, and Amazon OpenSearch Serverless resource types. For more information, see Supported resource types.

July 15, 2026

Added notes about recording delays for the Amazon Bedrock Agent Core Memory resource type

Updated the supported resource types table to note that recording configuration items (CIs) for AWS::BedrockAgentCore::Memory resource deletion events might take up to 360 hours to reflect in AWS Config. For more information, see Supported resource types.

July 7, 2026

Added service-linked role documentation for third-party cloud integrations

Added documentation for the AWSServiceRoleForConfigThirdParty service-linked role used for third-party cloud resource inventory and compliance evaluation. Updated the service-linked roles page to cover multiple roles. For more information, see Using Service-Linked Roles for AWS Config.

June 12, 2026

New resource types for AWS Config

With this release, you can use AWS Config to record configuration changes to new Amazon Bedrock and Amazon SageMaker AI Config resource types. For more information, see Supported resource types.

June 4, 2026

Updated service-linked recorder entries for AWS Security Hub

Updated the supported services table for service-linked configuration recorders. Added a Recorder name column. Updated the securityhub.amazonaws.com entry and added two new service-linked recorder entries (AWSConfigurationRecorderForSecurityHubAssets and AWSConfigurationRecorderForSecurityHubAssetsGlobal) with the securityhubv2.amazonaws.com service principal.

June 2, 2026

Clarify Advanced Query searchable fields support

Updated Advanced Query documentation to include more information about searchable fields and how that impacts retrieval in Advanced Query.

May 26, 2026

New resource types for AWS Config

With this release, you can use AWS Config to record configuration changes to new Amazon CloudWatch Application Signals, Amazon ARC Zonal Shift, AWS B2B Data Interchange, AWS Cost Explorer, AWS Clean Rooms, AWS CodeArtifact, Amazon Connect, Amazon EKS, Amazon GameLift, AWS Glue, Amazon CloudWatch Internet Monitor, AWS IoT, AWS IoT Wireless, Amazon Kinesis, AWS Private CA Connector for SCEP, Amazon Q Business, Amazon QuickSight, Amazon Route 53, AWS Systems Manager, and AWS Transfer Family Config resource types. For more information, see Supported resource types.

May 8, 2026

AWS Config updates NZISM conformance packs

With this release, AWS Config supports the following conformance packs:

May 7, 2026

Security IAM updates

The AWSConfigServiceRolePolicy and AWS_ConfigRole policies now grant additional permissions for bedrock, bedrock-agentcore, cloudtrail, cloudwatch, connect, dynamodb, elasticloadbalancing, lambda, license-manager, redshift, s3, s3express, and sagemaker services. For more information, see AWS managed policies for AWS Config.

May 5, 2026

AWS Config updates managed rules

With this release, AWS Config supports the following managed rules:

April 27, 2026

AWS Config deprecates managed rule

With this release, AWS Config is marking the managed rule ecs-task-definition-memory-hard-limit as deprecated.

April 3, 2026

AWS Config updates managed rules

With this release, AWS Config supports the following managed rules:

April 2, 2026

AWS Config supports new conformance packs

With this release, AWS Config supports the following conformance packs:

March 20, 2026

Security IAM updates

The AWSConfigServiceRolePolicy and AWS_ConfigRole policies now grant additional permissions for auditmanager, bcm-dashboards, bedrock, bedrock-agentcore, chime, dms, emr-containers, gameliftstreams, globalaccelerator, glue, lambda, medialive, mediapackagev2, outposts, qbusiness, redshift, rtbfabric, s3express, s3vectors, sagemaker, servicecatalog, ssm-contacts, ssm-guiconnect, sso, textract, transfer, and wisdom services. For more information, see AWS managed policies for AWS Config.

March 10, 2026

AWS Config updates managed rules

With this release, AWS Config supports the following managed rules:

March 4, 2026

Security IAM updates

The AWSConfigServiceRolePolicy and AWS_ConfigRole policies now grant additional permissions: application-autoscaling:DescribeScheduledActions, appsync:GetApiAssociation, cloudformation:DescribeStacks, cloudformation:GetStackPolicy, cloudformation:GetTemplate, cloudfront:GetKeyGroup, cloudfront:GetMonitoringSubscription, cloudfront:ListKeyGroups, connect:ListEvaluationFormVersions, cur:DescribeReportDefinitions, cur:ListTagsForResource, and permissions for datazone, docdb-elastic, ec2, fis, frauddetector, guardduty, iotfleetwise, iotsitewise, iotwireless, kendra, logs, mediaconnect, medialive, networkmanager, notifications, refactor-spaces, resource-explorer-2, route53resolver, securityhub, sms-voice, and workspaces-web services. For more information, see AWS managed policies for AWS Config.

February 17, 2026

Security IAM updates

The AWSConfigServiceRolePolicy and AWS_ConfigRole policies have been updated with comprehensive permissions for AWS resource configuration recording across over 100 AWS services. For more information, see AWS managed policies for AWS Config.

January 27, 2026

AWS Config updates managed rules

With this release, AWS Config supports the following managed rules:

January 9, 2026

AWS Config supports new permissions required for S3 Tables

With this release, AWS Config added new required permissions to record S3 Tables resource types. For more information, see