AI Briefing
Sign in

Control Per-User Athena Query Permissions in SageMaker Studio Using TIP and S3 Access Grants

·2026.09.29 11:44

Key point

Enabling TIP records the actual user ID in CloudTrail, enabling precise audit tracking.

1 / 16

Details

Previously, all users in SageMaker Studio shared the same Execution Role, making individual user identification and differentiated permission granting impossible. Enabling Trusted Identity Propagation (TIP) propagates user IDs from IAM Identity Center through SageMaker sessions to other AWS services, enabling fine-grained access control and audit tracking.

Core Mechanism and Auditing of TIP

The core of TIP is allowing the sts:SetContext action in addition to sts:AssumeRole in the Trust Policy of the Execution Role. This allows SageMaker to inject the actual user context into the Role session. Without TIP, the principal seen by the service is only the shared Role, but with TIP, both the shared Role and the actual user ID are passed together. In CloudTrail audit records, without TIP, only the Role ARN was recorded, making actor identification unclear, whereas with TIP, the actual user ID is recorded in the onBehalfOf field, enabling complete audit tracking.

Integrated Solution Components

This solution consists of IAM Identity Center (authentication), SageMaker Studio with TIP (ID propagation), S3 Access Grants (per-user S3 access), Lake Formation (table/column permissions), Athena with TIP Workgroup (query engine with IdC authentication mode), and CloudTrail (auditing). When creating a SageMaker Studio Domain, you must select 'Set up for organizations' and enable the 'Enable trusted identity propagation for all users on this domain' option.

Implementation Steps and Verification

During implementation, create an S3 Access Grants instance and integrate it with IAM Identity Center, and grant table permissions to specific users (e.g., emma) via Lake Formation. When creating an Athena Workgroup, select 'AWS IAM Identity Center' as the authentication method, and use an S3 bucket path with S3 Access Grants permissions as the query result storage location. When executing queries using PyAthena in SageMaker Studio, you can verify the actual user ID and the accessed S3 objects via the userIdentity.onBehalfOf field in the CloudTrail logs.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.