Select your cookie preferences

We use essential cookies and similar tools that are necessary to provide our site and services. We use performance cookies to collect anonymous statistics, so we can understand how customers use our site and make improvements. Essential cookies cannot be deactivated, but you can choose “Customize” or “Decline” to decline performance cookies.

If you agree, AWS and approved third parties will also use cookies to provide useful site features, remember your preferences, and display relevant content, including relevant advertising. To accept or decline all non-essential cookies, choose “Accept” or “Decline.” To make more detailed choices, choose “Customize.”

Document history for AMS Accelerate User Guide

Focus mode
Document history for AMS Accelerate User Guide - AMS Accelerate User Guide

The following table describes the important changes in each release of the AMS Accelerate User Guide. For notification about updates to this documentation, you can subscribe to an RSS feed.

ChangeDescriptionDate

Accelerate Update to RDS alarm monitoring threshold.

The RDS Average CPU Utilization alarm threshold has been changed from 75% to 90%.

February 20, 2025

Accelerate Update to AMS automatic remediation of alerts table.

The alert remediation table has been expanded with new content.

February 20, 2025

Accelerate New feature: Retain Alarms.

You can configure Alarm Manager to retain alarms in CloudWatch instead of automatic deletion.

February 20, 2025

Updated Self-service reports with new data options for aggregated report viewing

Added data options to include new Field Name: Admin Account ID, Dataset Field Name: aws_admin_account_id, and Definition: Trusted AWS Organization account enabled by the customer for the following Self-service reports:

  • Patch report (daily)

  • Backup report (daily)

  • Incident report (weekly)

  • Resource Tagger dashboard

  • Security Config Rules dashboard

January 28, 2025

Added additional AWS Trusted Advisor checks supported by Trusted Remediator

The following Trusted Advisor checks are now supported by Trusted Remediator:

  • Cost Optimization

    • c1cj39rr6v - Amazon S3 Incomplete Multipart Upload Abort Configuration

  • Security

    • Hs4Ma3G199 - RDS DB instances should publish logs to CloudWatch Logs

    • Hs4Ma3G326 - Amazon EMR block public access setting should be enabled

    • Hs4Ma3G272 - Users should not have root access to SageMaker AI notebook instances

    • Hs4Ma3G325 - EKS clusters should have audit logging enabled

    • HHs4Ma3G118 - VPC default security groups should not allow inbound or outbound traffic

    • Hs4Ma3G127 - API Gateway REST and WebSocket API execution logging should be enabled

    • Hs4Ma3G124 - Amazon EC2 instances should use Instance Metadata Service Version 2 (IMDSv2)

  • Fault tolerance

    • c1qf5bt013 - Amazon RDS DB instances have storage auto scaling turned off

    • 7qGXsKIUw - Classic Load Balancer Connection Draining

    • c18d2gz106 - Amazon EBS Not Included in AWS Backup Plan

    • c18d2gz107 - Amazon DynamoDB Table Not Included in AWS BackupPlan

    • cc18d2gz117 - Amazon EFS Not Included in AWS BackupPlan

    • c18d2gz105 - Network Load Balancer Cross Load Balancing

    • c1qf5bt026 - Amazon RDS synchronous_commit parameter is turned off

    • c1qf5bt030 - Amazon RDS innodb_flush_log_at_trx_commit parameter is not 1

    • c1qf5bt031 - Amazon RDS sync_binlog parameter is turned off

    • c1qf5bt036 - Amazon RDS innodb_default_row_format parameter setting is unsafe

    • c18d2gz144 - Amazon EC2 Detailed Monitoring Not Enabled

  • Operational Excellence

    • c18d2gz125 - Amazon API Gateway Not Logging Execution Logs

    • c18d2gz168 - Elastic Load BalancingDeletion Protection Not Enabled for Load Balancers

    • c1qf5bt012 - Amazon RDS Performance Insights is turned off

  • Performance

    • c1qf5bt021 - Amazon RDS innodb_change_buffering parameter using less than optimum value

    • c1qf5bt025 - Amazon RDS autovacuum parameter is turned off

    • c1qf5bt028 - Amazon RDS enable_indexonlyscan parameter is turned off

    • c1qf5bt029 - Amazon RDS enable_indexscan parameter is turned off

    • c1qf5bt032 - Amazon RDS innodb_stats_persistent parameter is turned off

    • c1qf5bt037 - Amazon RDSgeneral_logging parameter is turned on

January 28, 2025

Updated resource inventory spreadsheet

Updated resource inventory spreadsheet.

January 23, 2025

New AMS feature: Aggregated Self Service Reports

Aggregated self-service reporting (SSR) provides you a view of existing self-service reports aggregated at the organization level, cross-account.

January 21, 2025

New Accelerate patching feature: Patch Hooks

Use this feature to configure "hooks" with SSM Command documents to run operating system level commands before or after patching.

January 16, 2025

Update to How monitoring works section

Added information on a new feature, configuring alert notifications by resource, or instance ID, rather than by incident.

January 8, 2025

Update to Onboarding section of EKS Monitoring and Incident Management

Updated the onboarding procedure note to clarify when alert signals are suspended and resumed.

December 19, 2024

Member account log added to Trusted Remediator

You can use the Member accounts log to find the account ID, onboarded AWS Regions, and execution time of each member account.

December 19, 2024

Prerequisites for SSM Agent use

Content on blocking outbound traffic is updated.

December 4, 2024

Accelerate Monitoring and Incident Management for EKS is now supported in the Asia Pacific (Hong Kong) AWS Region

Asia Pacific (Hong Kong) is now a supported by Accelerate Monitoring and Incident Management for EKS

November 21, 2024

Updated Operations On Demand offerings table

The following operating systems are supported for in-place upgrades:

  • Microsoft Windows 2016 to Microsoft Windows 2022 and above

November 11, 2024

Accelerate Monitoring and Incident Management for EKS is now supported in the Africa (Cape Town) AWS Region.

Africa (Cape Town) is now a supported by Accelerate Monitoring and Incident Management for EKS

November 4, 2024

Updated Operations On Demand offerings table

The following operating systems are supported for in-place upgrades:

  • Microsoft Windows 2012 R2 to Microsoft Windows 2016 and above

  • Red Hat Enterprise Linux 7 to Red Hat Enterprise Linux 8

  • Red Hat Enterprise Linux 8 to Red Hat Enterprise Linux 9

  • Oracle Linux 7 to Oracle Linux 8

November 1, 2024

Updated Quick Start Template

Updated diagram, template parameters, and yaml template file.

October 28, 2024

Trusted Advisor checks added to Trusted Remediator in AMS

The following Trusted Advisor checks are now available in Trusted Remediator:

  • Z4AUBRNSmz - Unassociated Elastic IP Addresses

  • c18d2gz128 - Amazon ECR Repository Without Lifecycle Policy Configured

  • c18d2gz138 - DynamoDB Point-in-time Recovery

  • Hs4Ma3G323 - DynamoDBtables should have deletion protection enabled

  • Hs4Ma3G247 - Amazon EC2 Transit Gateway should not automatically accept VPC attachment requests

  • Hs4Ma3G308 - Amazon DocumentDB clusters should have deletion protection enabled

  • Hs4Ma3G299 - Neptune DB clusters should have deletion protection enabled

  • Hs4Ma3G306 - Amazon DocumentDB manual cluster snapshots should not be public

  • Hs4Ma3G109 - CloudTrail log file validation should be enabled

  • Hs4Ma3G217 - CodeBuild project environments should have a logging AWS Configuration4

  • Hs4Ma3G158 - SSM documents should not be public

  • Hs4Ma3G319 - Network Firewall firewalls should have deletion protection enabled

October 25, 2024

Updated Supported configurations

Updated supported Oracle Linux operating systems to 9.0-9.3, 8.0-8.9, 7.5-7.9.

October 24, 2024

New section added to Offboard from AMS Accelerate

Instructions on how to offboard with Alarm Manager and Resource Tagger dependencies added to Offboard from AMS Accelerate.

October 24, 2024

Resource Tagger dashboard is now available.

The Resource Tagger dashboard is now available in Self-service reporting.

September 26, 2024

You can now include multiple email addresses in tag-based alerts.

Multiple email addresses are now supported in tag-based alerts.

September 20, 2024

AMS Accelerate limits are now included in AMS patch management.

AMS Accelerate limits are included in Patch management - Create a patch maintenance window.

August 30, 2024

AMS Accelerate Account Discovery update

A new section in Account Discovery has been added for Amazon EC2 Instance Evaluation.

August 29, 2024

AMS Accelerate default patch baseline is now available for Ubuntu operating systems.

AMS Accelerate default patch baseline is now available for Ubuntu operating systems.

August 22, 2024

AMS Accelerate Account Discovery update

Four new AWS API calls have been added to the AWS CloudTrail Evaluation section in the operational check table.

August 2, 2024

Trusted Remediator now supports an additional check

Trusted Remediator now supports the security check Hs4Ma3G192 - RDS DB Instances should prohibit public access.

July 30, 2024

AMS now supports Amazon Route 53 Resolver DNS Firewall

AMS now supports Amazon Route 53 Resolver DNS Firewall

July 30, 2024

AMS Accelerate onboarding_role_minimal.zip now contains Terraform code

AMS Accelerate onboarding_role_minimal.zip now contains Terraform code.

July 30, 2024

Security Config Rules Dashboard

The Security Config Rules Dashboard is now available in Self-Service reporting.

July 24, 2024

AMS Accelerate now supports Oracle Linux 8.9, RHEL 8.10, and RHEL 9.4.

AMS Accelerate now supports Oracle Linux 8.9, RHEL 8.10, and RHEL 9.4.

July 5, 2024

AMS Accelerate account discovery process updated.

The account discovery process used when onboarding AWS accounts to AMS Accelerate is updated.

July 1, 2024

Trusted Remediator is now available.

Trusted Remediator, an AWS Managed Services solution that automates the remediation of AWS Trusted Advisor checks, is now available.

June 24, 2024

Amazon Route 53 Resolver DNS firewall events in Security Incident Response.

AMS now monitors Amazon Route 53 Resolver DNS firewall events in Security Incident Response

June 21, 2024

Updated supported operating systems

AMS Accelerate now supports AlmaLinux 8.3-8.9, 9.0-9.2 (AlmaLinux is only supported with x86 architecture)

June 19, 2024

Automatic instance profile limit now increases if the default is met.

AMS now increases the default instance profile limit to 20 if the default limit of 10 is reached.

June 18, 2024

AMS SSM Agent automatic installation feature now enabled by default.

The AMS SSM Agent automatic installation feature is enabled by default for accounts onboarded after 6/03/2024.

June 7, 2024

Security FAQ added to Security management.

A Security FAQ is now available that covers common questions about the security best practices, controls, access models, and audit mechanisms used when an AMS operations engineer or automation accesses your accounts.

June 3, 2024

Additional AWS Regions now supported by Monitoring and Incident Management for Amazon EKS.

Three additional AWS Regions are now supported by Monitoring and Incident Management for Amazon EKS.

May 23, 2024

Service request patch notifications are now sent in advance of Patch Maintenance windows.

AMS Accelerate patching creates a new service request 4 days in advance of a Patch Maintenance window. You can use the service request to communicate with AMS for adjustments to the patch or to skip a patch.

May 3, 2024

Alert thresholds added to the AMS Accelerate EKS monitoring baseline alerts table.

Detailed alert thresholds are now available in the Baseline alerts table for Amazon EKS monitoring.

May 3, 2024

Updated: Alarm Manager Configuration Profiles.

Added notes about creating Anomaly Detection alarms with Alarm Manager.

April 25, 2024

Additions to Resource Tagger configuration profiles.

DynamoDB tables and Amazon S3 buckets are now available in Resource Tagger

April 25, 2024

Added Planned Event Management (PEM) information section.

Detailed information about the PEM service offering is now available in the AMS Accelerate User Guide.

April 25, 2024

AMS supports Red Hat Enterpise Linux (RHEL) 9.x.

AMS supports Red Hat Enterprise Linux (RHEL) 9.x.

April 25, 2024

AMS Accelerate supports reporting for all AWS Region configurations.

AMS Accelerate supports SSM Inventory Reporting for all AWS Region configurations.

April 25, 2024

Updated: AWS managed policies.

Updated the AWSManagedServicesDeploymentToolkitPolicy with new ECR permissions.

April 4, 2024

Updated: Resource Tagger Configuration Profiles section

Added AWS::EFS::FileSystem to the ResourceType list.

March 21, 2024

Updated: Incident reports and service requests in Accelerate section.

Changed the topic title to Incident reports, service requests, and billing questions in Accelerate. Added a new section, Billing questions.

March 21, 2024

Updated: How service request management works section.

Added clarification on how AMS handles service requests that contain a feature request or a bug.

March 21, 2024

Updated: Create aws_managedservices_onboarding_role role with AWS CloudFormation section

Added commands to create the role from AWS CloudShell.

March 21, 2024

Updated: (Optional) Quick Start template

Added commands to download the template from AWS CloudShell.

March 21, 2024

New resource types available for Alarm Manager configuration profiles.

Added resource types for Amazon FSx, Amazon EFS, and Elasticsearch to Alarm Manager configuration profiles.

March 21, 2024

Additional pseudoparameter substitutions available for configuration profile.

Added Amazon EFS and Amazon FSx pseudoparameter substitutions.

March 21, 2024

Added new section to Features in the Service description topic.

Added a new section, Service request management under AMS Accelerate features.

March 21, 2024

New columns added to the self-service reporting Weekly Incident report

New columns were added to the Weekly Incident report so that you can filter for incidents based on quarter, month, week, or day that the incident was created or resolved.

March 11, 2024

Earlier updates

The following table describes the important changes to the documentation of the AMS Accelerate guide prior to March 2024.

Change Description Date
Improvements for AMS Accelerate CloudTrail trail onboarding

Improvements for AMS Accelerate CloudTrail trail onboarding:

  • Collect all bucket policies in a single block

  • Remove the second AWS Organization ID in the policy statements

  • Clarify customer environment requirements

For more information, see Review and update your configurations to enable AMS Accelerate to use your CloudTrail trail.

February 23, 2024
Updated: Account onboarding process.

Restructured the Account onboarding process section to make the steps more clear. Also aded an optional Quick Start template for onboarding features.

See (Optional) Quick Start template in Accelerate.

February 22, 2024
Updated: Offboarding AMS Accelerate.

Updated the AMS Accelerate offboarding considerations section to indicate that the ams-access-management CloudFormation stack and ams-access-management IAM role aren't deleted by the offboarding process.

See AMS Accelerate offboarding effects.

February 22, 2024
Updated: Configuration compliance in Accelerate.

Changed "Incident Report" to "Service Request" where applicable to avoid confusion on these terms.

See Configuration compliance in Accelerate.

February 22, 2024
Updated: Account discovery in Accelerate.

Reorganized Account discovery in Accelerate to better group prerequisites with the relevant section.

See Step 1. Account discovery in Accelerate.

February 22, 2024
Renamed: AMS Patch reporting to AMS host management.

Renamed AMS Patch reporting to AMS host management and renamed the report, Patch Details report, to SSM Agent Coverage report.

See AMS host management reports.

February 22, 2024
Updated Operations on Demand Catalog

Updated the Operations on Demand catalog of offerings table to remove references to "health" in Amazon EKS cluster maintenance.

See Requesting AMS Operations On Demand.

February 22, 2024
Updated AMS Event Router

Updated the AMSCoreRule in the AMS Event Router section.

See Using Amazon EventBridge Managed Rules in AMS.

February 22, 2024
Updated Supported Operating Systems.

Updated Supported Operating Systems to include SUSE Linux Enterprise Server 15 SP5.

See Supported configurations.

February 22, 2024
Updated EC2 volume usage remediation automation

Updated the EC2 volume usage remdiation automation section with correct capacity expansion schedule.

See EC2 volume usage remediation automation.

February 22, 2024
Updated: Review and update your configurations to enable Accelerate to use your CloudTrail trail Updated the AMS Accelerate Organization CloudTrail S3 bucket policy section. See Review and update your configurations to enable AMS Accelerate to use your CloudTrail trail February 15, 2024
Added new feature: SSM Agent auto installation

Added a new section for SSM Agent auto installation

See SSM Agent automatic installation.

January 26, 2024
Updated: Supported configurations

Added information regarding the supported versions of AWS Control Tower

See Supported configurations.

January 26, 2024
Updated: AMS Patch reporting.

Removed three sections from AMS Patch reporting:

  • Patch Instance Details Summary report

  • Patch Details report

  • Instances that Missed Patches report

See AMS host management reports.

December 22, 2023
Updated: Accelerate onboarding prerequisites.

Updated the support plans required to onboard AMS Accelerate.

See Accelerate onboarding prerequisites.

December 15, 2023
Updated: Create a patch maintenace window.

Removed Default patch cycle sectio as this feature is deprecated.

See Create a patch maintenance window in AMS.

December 13, 2023
Updated: Notification settings in Accelerate.

Clarified what email is used for notifications.

See Notification settings in Accelerate for more information.

December 12, 2023
Updated: AMSAccelerateCustomerAccessPolicies template.

Updated the AMSAccelerateCustomerAccessPolicies template to correct a syntax error.

See Permissions to use AMS features for more information.

December 12, 2023
Added: Change request security reviews

Added a new section Change request security reviews under Security Management.

See Change request security reviews for more information.

December 11, 2023
Updated: resource_inventory.xlsx

Updated the resource_inventory.xlsx to include Security Analyst roles.

See Resource inventory for Accelerate for more information.

November 17, 2023
Updated: ams-access-admin-operations role description

Updated ams-access-admin-operations description.

See Why and when AMS accesses your account and Authenticating with identities in AMS Accelerate for more information.

November 17, 2023
Updated: AMS Accelerate offboarding considerations

Updated Security section to clarify what is available from Amazon GuardDuty and AWS Config rules after offboarding.

See AMS Accelerate offboarding effects for more information.

November 17, 2023
Added: Monitoring and Incident Management for Amazon EKS

Monitoring and Incident Management for Amazon EKS monitors your Amazon EKS resources for failures, performance degradation, and security issues.

See Monitoring and incident management for Amazon EKS in AMS Accelerate for more information.

November 14, 2023
Updated: Tagging

Added information on customer-provided tagging.

See Customer-provided tags in Accelerate for more information.

November 7, 2023
Updated: Resource Tagger Configuration Profiles

Added AWS::AutoScaling::AutoScalingGroup, AWS::EKS::Cluster, AWS::Elasticsearch::Domain, and AWS::FSx::FileSystem to the Filter section.

See Resource Tagger Configuration Profiles in AMS Accelerate for more information.

October 27, 2023
Updated: Service Description

Added Ubuntu 22.04 to Supported Operating Systems. See Service description

September 29, 2023
Updated: AMS Accelerate Onboarding Prerequisites Added a note to AMS Accelerate VPC endpoints to include CloudFormation template. See Accelerate onboarding prerequisites. September 29, 2023
Updated: Detect Removed endpoint protection type from the AMS Accelerate security response. See Detect. September 29, 2023
Updated: Alerts from Baseline Monitoring in AMS Added AWS Outposts to the Alerts from Baseline Monitoring table. See Detect monitoring-default-metrics. September 29, 2023
Updated: Create aws_managedservices_onboarding_role role with AWS CloudFormation Updated screenshot for Specify Stack Details. See Create aws_managedservices_onboarding_role with AWS CloudFormation for Accelerate. September 29, 2023
Updated: Amazon EventBridge Managed Rules deployed by AMS Accelerate

Added new AMS Accelerate Amazon EventBridge Managed Rule AMSCoreRule.

Updated AMS Accelerate Amazon EventBridge Managed Rule AMSAccessRolesRule to add a new role.

See Amazon EventBridge Managed Rules deployed by AMS for more information.

September 19, 2023
Updated: Alarm Manager Configuration Profiles

Added AWS Outposts pseudoparameter substitution identifiers. See Monitoring and event management in AMS Accelerate.

September 11, 2023
Updated: Resource Tagger Configuration Profiles

Added AWS Outposts resource type. See Accelerate Configuration profile: pseudoparameter substitution.

September 11, 2023
Updated: Supported services

Added Amazon Elastic File System to the Services monitored by CloudWatch alarms section.

See Service description for more information.

September 6, 2023
Updated: Patch monitoring and failure remediation

Added the following note to Using Patch Orchestrator section:

"Patch failure alerts aren't created for instances that have unsupported operating systems, or that are stopped during the maintenance window"

See Understand patch management in AMS Accelerate for more information.

September 6, 2023
Updated: Clarified Response to malware events runbook

Clarified Response to malware events runbook for Security Incident response. See Security Incident Response in AMS for more information.

September 6, 2023
Updated: Connecting your Accelerate account with Transit Gateway

Clarified steps for Connecting a new Accelerate account VPC to the AMS Multi-Account Landing Zone network (creating a TGW VPC attachment): See Connecting your Accelerate account withTransit Gateway for more information.

September 5, 2023
Updated: Alerts from baseline monitoring in AMS

Removed reference to two deprecated alarms AMSReadLatencyAlarm and AMSWriteLatencyAlarm. See Alerts from baseline monitoring in AMS for more information.

September 5, 2023
Added: AMS Event Router

Added documentation for AMS Event Router See Using Amazon EventBridge Managed Rules in AMS for more information.

September 5, 2023
Updated: List of Alarm Manager pseudoparameters.

Updated the list of Alarm Manager pseudoparameters. EC2 instance name parameter was added to EC2 instance and EC2 disk alarm configurations. See Accelerate Configuration profile: pseudoparameter substitution for more information.

August 29, 2023
Added: AMS Access Offboarding

Added consideration when offboarding AMS Access. See AMS Accelerate offboarding effects.

August 24, 2023
Added: AMS Security Incident Response

Added documentation for using AMS Security Incident Response. See Security Incident Response in AMS .

August 18, 2023
Updated: AMS Accelerate access roles

Corrected a typo in the role names. See AWS Identity and Access Management in AMS Accelerate.

August 10, 2023
Updated: Policy statements

Replaced hardcoded role names with wildcards. See Review and update your configurations to enable AMS Accelerate to use your CloudTrail trail.

August 10, 2023
Updated: List of monitored services with EFS alerts.

Updated the list of monitoring services with new EFS alerts for AMS baseline monitoring. 4 new EFS alert types were added. See Alerts from baseline monitoring in AMS for more information.

August 03, 2023
Updated: Accelerate resource inventory table

Removed ams-backup-config-rule-stack and related resources. See Resource inventory for Accelerate.

July 18, 2023
Updated: AMS Accelerate access roles

Removed roles ams-backup-config-rule-st-amsBackupAlertConfigRule-<8-digit hash> and ams-backup-config-rule-st-amsBackupPlanConfigRuleH-<8-digit hash>. See AWS Identity and Access Management in AMS Accelerate.

July 18, 2023
Updated: List of monitored RDS alerts.

Updated the list of RDS alerts for AMS baseline monitoring. 9 new RDS alert types were added and 3 existing RDS alert types were removed. See Alerts from baseline monitoring in AMS for more information.

June 19, 2023
New: AMS Accelerate access roles

Added new access roles for AMS Security.

June 16, 2023
New: AMS Accelerate CloudTrail log management can now use customer CloudTrail trails.

Updated Accelerate supported options for CloudTrail log management, including Accelerate deployed trail or integration with customer managed CloudTrail account or Organization trail. See Review and update your configurations to enable AMS Accelerate to use your CloudTrail trail for more information.

June 09, 2023
Updated: AMS Accelerate Config Rules Response Configuration Report.

Updated on-request reporting for AWS Config Rules Response Configuration Report. See Accelerate updates to on-request reporting. See AMS Config Rules Response Configuration report.

May 26, 2023
Updated: Service Billing Start Date policy.

Updated definitions of Billing Start Date in AMS key terms.

May 15, 2023
Updated: AWS managed policies.

Updated the AWSManagedServicesDeploymentToolkitPolicy with new CFN and ECR permissions, and scoped down existing actions with wildcards. See Accelerate updates to service-linked roles. See Accelerate updates to service-linked roles.

May 09, 2023
Updated: Access role policy links.

The access roles can now be downloaded directly from Accelerate S3 bucket locations.

See Why and when AMS accesses your account and AWS Identity and Access Management in AMS Accelerate.

Updated: Monthly Billing Self-Service Report.

Added note: The Monthly Billing reports are only available in a Management Payer account (AMS Advanced multi-account landing zone), but are available for all linked AMS Accelerate-managed accounts.

See Billing report (monthly).

April 13, 2023
Updated: List of Alerts.

Removed CloudTrail references.

See Log management in AMS Accelerate.

April 13, 2023
Updated: List of Alerts.

Added three new SSM agent alerts.

See Alerts from baseline monitoring in AMS.

April 13, 2023
Updated: Accelerate Prerequisites.

Clarified that Accelerate requires one of four AWS Support plans be in place and excludes the Developer plan.

See Accelerate onboarding prerequisites.

April 13, 2023
Updated: Accelerate service-linked role policy.

The Contacts Service policy zip file has been updated.

See AWS managed policies for AMS Accelerate.

April 13, 2023
Updated: AMS Resource Scheduler.

Incorrect role name, AWSManagedServices-DescribeScheduleOrPeriod, corrected to AWSManagedServices-DescribeScheduleOrPeriods. See Cost optimization with AMS Resource Scheduler.

April 13, 2023
Updated: AWS managed policies.

Updated Customized findings responses with instructions for updating custom reponses in single or multiple accounts.

April 13, 2023
Updated: Resource Tagger

Added warnings about "specifying the name for your new configuration (SampleConfigurationBlock in the provided example) as you may inadvertently override the AMS-managed configuration with the same name". See Resource Tagger use cases in AMS Accelerate.

March 16, 2023
Updated: Patch RACI

Several updates and clarfications to the RACI for patching. See Service description.

March 16, 2023
Updated: Actions in deployment toolkit SLR JSON

Updated policy and actions. See: Using service-linked roles for AMS Accelerate.

March 16, 2023
Updated: Auto remediation

Removed LVM support for EC2 volume automation. See: AMS automatic remediation of alerts.

March 16, 2023
Updated: Accelerate Onboarding.

Clarified use of roles, espcially the minimal role The template to create AMS roles.

March 16, 2023
Updated: Self-service reporting.

Daily backup reports now support primary and secondary regions. Both are reported in the Resource Region field of Backup report (daily).

March 16, 2023
Updated: Patching guidance

Added a warning not to customize the default patching baselines, which are managed by AMS. Instead, create a new custom patching baseline. See: Default patch baseline and Custom patch baseline with AMS Accelerate.

March 16, 2023
Updated Service Termination policy.

Updated definitions of Service Termination and Service Termination Date in AMS key terms. Termination notcies must be issued by the 20th day of the month prior to your last full month.

March 16, 2023
Updated: AWS managed policies.

Clarified policy name: Contacts service-linked role for AMS Accelerate.

Feb 16, 2023
New: AWS managed policies.

Added policy: Contacts service-linked role for AMS Accelerate.

Feb 16, 2023
Updated: Configuration compliance.

Fixed a misspelled word in: Configuration compliance in Accelerate.

Feb 16, 2023
New Content: Unsupported OSes

Added information on what services AMS provides for unsupported operating systems (OSes), see Capabilities for unsupported operating systems in Accelerate.

Feb 16, 2023
Updated: Create patch windows

Added a link for using CloudShell to Create a maintenance window with the Systems Manager command line interface (CLI) for AMS Accelerate.

Feb 16, 2023
Updated Content: Onboarding management resources

Updated the zipped JSON templates in The template to create AMS roles.

Feb 16, 2023
New Content: Configuration Compliance

Added a new topic: Customized findings responses.

Feb 16, 2023
New: AWS managed policies.

Added policy: Amazon EventBridge rule service-linked role for AMS Accelerate.

Feb 07, 2023
Updated: AWS managed policies.

Updated the AWSManagedServicesDeploymentToolkitPolicy with new S3 permissions. See Accelerate updates to service-linked roles.

Jan 30, 2023
New opt-in region: CPT.

AMS Accelerate is now available in the Capetown (CPT) opt-in region. To opt in, see Managing AWS Regions.

Jan 12, 2023
Updated: Service Description.

Added FSx services monitored by CloudWatch alarms to Service description.

Jan 12, 2023
Updated: Monitoring default metrics.

Added 6 FSx alarms to Alerts from baseline monitoring in AMS.

Jan 12, 2023
Updated: AMS patterns.

Added Customize Cloudwatch Alarm Notifications to AMS patterns.

Jan 12, 2023
Updated: Onboarding management resources.

Updated the table of templates, adding a row for ams-onboarding-ssm-execution-role in The template to create AMS roles.

Jan 12, 2023
Updated: Configuration compliance.

Additional details for requesting custom remediations (in the Important box) on Configuration compliance in Accelerate.

Jan 12, 2023
Updated: Service-linked-role permissions.

Removed older or duplicated permissions. See Using service-linked roles for AMS Accelerate.

Dec 15, 2022
Updated: Patch management, maintenance windows.

Added guidance to console instructions, step 5, for creating a maintenance window. See Create a maintenance window from the Systems Manager console for AMS Accelerate.

Dec 15, 2022
New: Patch management section.

Added a section for Patch Tuesday maintenance windows. See Create a recurring "Patch Tuesday" maintenance window from the AMS console (recommended).

Dec 15, 2022
Updated: AMS Resource Scheduler.

Updated the AWS CloudFormation stack name. See Using resources with AMS Resource Scheduler.

Dec 15, 2022
Updated: Tag your resources for backup.

Added guidance for using AMS Resource Tagger. See Tag your resources to apply AMS backup plans.

Dec 15, 2022
Updated: Select a backup plan.

Indicated which plans offer continuous backup. See Select an AMS backup plan.

Dec 15, 2022
Updated: AMS Resource Scheduler.

Updated the AWS CLI example for deleting a period or schedule. See Working with periods and schedules in AWS Managed Services Resource Scheduler.

Dec 15, 2022
Updated: AWS managed policies.

Added the AWSManagedServicesDeploymentToolkitPolicy. See AWS managed policies for AMS Accelerate.

Dec 15, 2022
New: Added section describing the AMS new service-linked role, AWSServiceRoleForManagedServices_DetectiveControlsConfig.

Added GovCloud regions and permissions. See Detective controls service-linked role for AMS Accelerate.

Dec 15, 2022
New: AWS-managed policy

Added section describing how the AWS-managed policy, AWSManagedServices_AlarmManagerPermissionsBoundary, is used in the service-linked role policy, AWSManagedServices_AlarmManager_ServiceRolePolicy, to restrict permissions of IAM roles created by the service-linked role AWSServiceRoleForManagedServices_AlarmManager. See AWS managed policies for AMS Accelerate.

Dec 15, 2022
Updated: Operations on Demand.

Added offerings: SQL Server on EC2 Operations and AMI Building and Vending. See Operations On Demand.

Nov 10, 2022
Updated: Monitoring and event management.

Updated explanation of service notifications and incident reports. See How monitoring works.

Nov 10, 2022
Updated: Service-linked role regions

Added GovCloud regions and permissions. See Using service-linked roles for AMS Accelerate.

Nov 10, 2022
New: Service-linked role.

Added new role: AWSServiceRoleForAMSDetectiveControls.

See Detective controls service-linked role for AMS Accelerate.

Nov 10, 2022
Updated: Access management.

Updated subsections with improved instructions. See Access management in AMS Accelerate.

Nov 10, 2022
Updated: Service description.

Updated AMS Patterns in the RACI matrix. See Service description.

Nov 10, 2022
Updated: AMS patterns.

Customers are responsible for pattern deployments. See AMS patterns.

Nov 10, 2022
Updated: Offboarding.

Added details of what happens to specific Backup and Monitoring resources during offboarding. See Offboard from AMS Accelerate.

Nov 10, 2022
Updated: Patch management..

Updated and shortened guidance regarding IAM policies. See Creating an IAM role for on-demand patching of AMS Accelerate.

Nov 10, 2022
New: links to architecture diagrams.

Added links to AMS Reference Architecture Diagrams to various topics. For example, see Monitoring and event management in AMS Accelerate.

Nov 10, 2022
New: Operations on Demand offering

Added "Landing Zone Accelerator Operations". See Operations On Demand.

Oct 13, 2022
Update: Monitoring management. Alerts generate incident reports, not service requests

How monitoring works.

Oct 13, 2022
New: Creating a patch maintenance window with an Accelerate-custom CFN template

AWS CloudFormation patch window configuration templates. See Create a patch maintenance window in AMS.

Sept 15, 2022
Updated: Offboarding

Emphasized that backup plans in Accelerate no longer work after offboarding. See Offboard from AMS Accelerate.

Sept 15, 2022
Updated: CloudWatch configuration change details

Corrected a mistake in the Windows and Linux examples. See CloudWatch configuration change details.

Sept 15, 2022
Updated: Using AMS Resource Scheduler

Added guidance about Cost Allocation Tags. See Cost estimator in AMS Resource Scheduler.

September 15, 2022
Updated: AMS Config Rule Library

Added two ams-eks- config rules to the Table of Rules. See AMS Config Rule library.

September 15, 2022
Updated: Backup Management

Removed the misleading label PITR (point-in-time-recovery) from backup plan titles and descriptions. See Select an AMS backup plan.

September 15, 2022
Updated: Accelerate Service Description

Updated descriptions of config rules and canaries. See Service description.

September 15, 2022
Updated: Service Description, Supported Configurations

Removed end-of-service date for Windows 2008 R2. Accelerate does not support Windows 2008. See Supported configurations.

August 11, 2022
Updated: Service Description, Roles and Responsibilities

Updated the RACI table. Removed ELB access logs from the last row of the Networking section. We do not enable ELB access logs for Accelerate customers. See Roles and responsibilities.

August 11, 2022
Updated: Configuration Compliance

Corrected a typo in the Table of Rules, Frameworks column. NIST-CSF was incorrectly listed as NIST-CIS. See Configuration compliance in Accelerate.

August 11, 2022
New: Accelerate Offboarding

Considerations and process for offboarding. See Offboarding AMS Accelerate.

August 11, 2022
Updated: List of pre-installed SSM agents' operating systems

Added "Ubuntu Linux 18.04 and 20.04" to the list. See Onboarding EC2 instances to Accelerate.

August 11, 2022
New: Resource Scheduler

Use AMS Resource Scheduler to cost optimize by stopping and starting resources only as needed. See Cost optimization with AMS Resource Scheduler.

July 14, 2022
Updated: Service Description for Resource Scheduler

Several sections of the service description were updated for the new Resource Scheduler offering. See Service description.

July 14, 2022
New: AMS Patterns

AMS offers pattern templates, a generalized solution that solves for a family of use cases in the AMS managed environment. First pattern on offer: AMS patterns.

July 14, 2022
New: Cost optimization note

Added a note explaining how costs can increase with resource usage. See Resource inventory for Accelerate.

July 14, 2022
Updated: AMS Config Rules

Reorganized the tables in the AMS Config Rule library. The HTML table has fewer columns, to make it easier to read at a glance. The downloadable spreadsheet has additional columns to allow sorting and filtering.

July 14, 2022
Updated: Access Management

Updated the sample CloudFormation template in Permissions to use AMS features. The AMSAccelerateAdminAccess policy now includes the AmsResourceSchedulerPassRolePolicy and IAMReadOnlyPolicy policies.

July 14, 2022
Updated: Self-Service Reporting

Added instructions for encrypting AWS Glue metadata with KMS keys. See box labeled Important on Self-service reports.

July 14, 2022
Updated: AMS baseline monitoring Added DeleteRecoveryPoint backup alert. Alerts from baseline monitoring in AMS July 14, 2022
Updated: Supported operating systems Added End of Support date for Amazon Linux 2. Service description July 14, 2022
Updated: AMS Reporting Added note about Opt-in Regions. Reports and options July 14, 2022
Resource Scheduler

Added information about onboarding and using AMS Resource Scheduler to assist in cost optimization by scheduling resource stop and start times. Also, updated the Accelerate service description to include mention of Resource Scheduler. Additionally, updated the Amazon Linux 2 supported end of support date to 2024. See Cost optimization with AMS Resource Scheduler and Service description

June 30, 2022
New alarm

Added a AWS Backup alarm. Alerts from baseline monitoring in AMS

June 21, 2022
New content

Added the service-linked role content. Using service-linked roles for AMS Accelerate

June 16, 2022
AWS Network Firewall Operations added to Operations on Demand (OOD) catalog of offerings. Operations On Demand June 16, 2022
Added problem management feature description. Service description June 16, 2022
Added note about the set of config rules that does not support in particular opt-in regions. Configuration compliance in Accelerate June 16, 2022
Updated content

Configuration compliance. "AMS Config Rule library" -> "Table of rules", was updated and removed to ZIP only. Configuration compliance in Accelerate

June 16, 2022
Removed escalation emails. Escalation path June 16, 2022

Moved topic list to below opening paragraphs. What is AMS Accelerate?

June 16, 2022

Updated the auto remeditation content. AMS automatic remediation of alerts

June 16, 2022
Updated content: Service Description

Added EKS to the list of services monitored by AMS Config Rules in Supported services.

Updated monitoring description in RACI table in Roles and responsibilities.

May 12, 2022
Updated content: Configuration Compliance

Added EKS-related config rules. See Configuration compliance in Accelerate.

May 12, 2022
Updated content: Getting Started, Account Discovery

Added a newer version of the AwsAccountDiscoveryCli script (in the Account Discovery Changelog zip file) in Step 1. Account discovery in Accelerate.

May 12, 2022
Updated content: Monitoring, default metrics

Updated trigger conditions for ALB-related metrics. See Alerts from baseline monitoring in AMS.

May 12, 2022
Updated content: Patching onboarding

Added an explicit patching prerequisite: you need to opt-in to EBS. See Onboarding patching in Accelerate.

May 12, 2022
Updated content: Accelerate resource inventory table

Changed ams-detective-controls-config-rules-cdk rules, added rules for ams-detective-controls-recorder-cdk and ams-detective-controls-infrastructure-cdk. See Resource inventory for Accelerate.

April 14, 2022
Updated content: Configuration Compliance

Introduction to industry standards, config rules, and types of responses. Emphasizes that customers do not choose individual config rules or responses. Configuration compliance in Accelerate.

April 14, 2022
Updated content: Service Description

Moved the existing Scope of Changes section under Roles and Responsibilities. See Roles and responsibilities.

April 14, 2022
Updated content: Tagging and Monitoring

Added AWS::Synthetics:Canary to lists of allowed Resource Types for tagging and monitoring. See Resource Tagger Configuration Profiles in AMS Accelerate and Accelerate Configuration profile: pseudoparameter substitution.

April 14, 2022
Updated content: Accelerate Prerequisites

Added SSM-required bucket permissions to Amazon EC2 Systems Manager in Accelerate.

April 14, 2022
New content: Patching and Monitoring

Added sample code to use Cloudformation to deploy tagging and monitoring configurations. See Deploying a configuration profile with AWS CloudFormation for Accelerate and Using AWS CloudFormation to deploy Accelerate configuration changes.

March 10, 2022
Updated content: Patch maintenance console

Reordered steps in Create a maintenance window from the Systems Manager console for AMS Accelerate to match the console interface.

March 10, 2022
Updated content: Patch maintenance CLI

Updated CLI parameters (schedule, duration, and cutoff) for Create a maintenance window with the Systems Manager command line interface (CLI) for AMS Accelerate

March 10, 2022
New content: Auto Instance Config

Added definition of AMSInstanceProfileBasePolicy to IAM permissions change details

March 10, 2022
New content: Onboarding

Added a sample Linux command to Outbound internet connectivity in Accelerate

March 10, 2022
New content: Onboarding

Added a least-privilege option to The template to create AMS roles.

March 10, 2022
Updated content: Accelerate escalation instructions

Added guidance, links, and email contacts to Escalation path

March 10, 2022
Updated content: Supported Configurations

AMS expects to end support for RHEL 6 and CentOs on March 14, 2023. See Supported configurations

March 10, 2022
Updated content: Resources table

Added AMS access IAM roles to Resource inventory for Accelerate resources table

March 10, 2022
Updated content: Onboarding and Backup

Added instructions for opting in to AWS Backup to Onboarding AWS Backup in Accelerate and Continuity management in AMS Accelerate

March 10, 2022
Updated content: Access Management

Removed Advanced-specific instructions from Accelerate guidance How and when to use the root user account in AMS.

March 10, 2022
Updated content: Supported Configurations

AMS now supports Oracle Linux 8.3 and Ubuntu 18.04 and 20.04. See Supported configurations.

February 28, 2022
Updated content: Service Level Agreement

Updated the downloadable Service Level Agreement in Supported services.

February 28, 2022
Updated content: Access Management

Updated How AMS accesses your account with FAQs for AMS operator console roles and a warning not to modify or delete them.

February 28, 2022
Updated content: Alarm Manager

Updated Accelerate Configuration profile: monitoring. Alarm Manager is no longer limited to single-metric alarms.

February 28, 2022
Updated content: Getting Started

Updated Step 2. Onboarding management resources in Accelerate. Added an IAM role with minimal access for onboarding resources.

February 28, 2022
New content: Scope of Changes in Service Description

Added a new section,Scope of changes performed by AMS Accelerate that emphasizes boundaries and actions that AMS Accelerate does not perform.

February 10, 2022
Updated content: Getting Started

New onboarding process starts with setting up default features and configurations before customizing. Subsections contain feature-specific goals and related links. See Getting Started with AMS Accelerate.

February 10, 2022
Updated content: AMS Backup Management.

Shortened and reorganized the Continuity management in AMS Accelerate chapter for readability.

February 10, 2022
Updated content: Tagging

Added a Tagging Tools section to accommodate code samples for CloudFormation and other tools. See Tagging in AMS Accelerate.

February 10, 2022
Updated content: Baseline Monitoring

Improved trigger condition for RedShift cluster alarm reduces false alarms during maintenance. See Alerts from baseline monitoring in AMS.

February 10, 2022
Updated content: Patching

Updated sample CLI command to register a maintenance window. See Create a maintenance window with the Systems Manager command line interface (CLI) for AMS Accelerate.

February 10, 2022
Updated content: AWS Config Rules Inventory.

Removed deprecated config rule ams-nist-cis-ec2-security-group-attached-to-eni from the AWS Config Rules Inventory table. See Table of Rules.

January 27, 2022
New content: Creating patch maintenance windows.

Added a link to the SSM tutorial and sample commands for creating patch maintenance windows from the command line. See Create a maintenance window with the Systems Manager command line interface (CLI) for AMS Accelerate.

January 27, 2022
New content: Resource Tagger recognizes new Auto Scaling Groups (ASG) resource type.

Added Auto Scaling Groups to the resource types filterable with Resource Tagger configuration profiles. See Syntax and structure.

January 13, 2022
New content: Additional backup plans and vaults.

Added new backup plans and vaults to mitigate high-risk scenarios including ransomware attacks. See View backups in AMS vaults and View backups in AMS vaults.

January 13, 2022

On this page

PrivacySite termsCookie preferences
© 2025, Amazon Web Services, Inc. or its affiliates. All rights reserved.