---
格式版本: 2
标题: "Amazon SageMaker notebooks now support trusted identity propagation"
原文链接: "https://aws.amazon.com/cn/about-aws/whats-new/2026/08/amazon-sagemaker/"
发布日期: "2026-08-19"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "llm:local:original_script_field"
发布时间证据: "postDateTime: 2026-08-19T20:25:00Z"
发布时间校准原因: "候选日期来自原始脚本字段，明确标注为文章发布时间，且与YAML发布日期一致，无冲突。"
发布时间校准置信度: "1"
发布时间候选数量: 1
发布时间严格候选数量: 0
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-20T10:38:22+08:00"
发布时间仲裁状态: "confirmed"
发布时间仲裁尝试次数: 1
发布时间仲裁耗时毫秒: 13164
发现时间: "2026-08-20T10:31:30+08:00"
入库时间: "2026-08-20T02:38:37.691Z"
来源平台: "固定入口"
搜索渠道: "fixed_url"
搜索词: "https://aws.amazon.com/new"
匹配关键词:
  []
相关厂家:
  - "AWS"
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 15
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "内容为Amazon SageMaker Notebooks的软件身份传播功能，涉及Athena/Redshift/EMR，与超节点、AI Rack、机柜级AI基础设施、供电散热互连等主题完全无关。来源权威但主题不相关，不提供有效信号。"
AI质检模型: "ali-deepseek-v4-flash"
AI质检时间: "2026-08-20T10:39:05+08:00"
AI主题相关性: 0
AI来源权威性: 15
AI新颖性: 0
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 0
AI摘要: "Amazon SageMaker Notebooks 现已支持可信身份传播，可对接 Athena、Redshift 和 EMR Serverless，实现按用户的数据访问控制；"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T03:16:49.940Z"
采集批次: "2026年8月20日10点15分53秒"
采集批次ID: "20260820-101553-437"
去重键: "https://aws.amazon.com/cn/about-aws/whats-new/2026/08/amazon-sagemaker"
---

Amazon SageMaker Notebooks now support Trusted Identity Propagation (TIP) with Amazon Athena, Amazon Redshift, and Amazon EMR Serverless, enabling per-user access control for data analytics.

When connected to a TIP-enabled compute in a TIP-enabled Project, each notebook user's IAM Identity Center identity flows through to AWS Lake Formation, ensuring they see only the tables, columns, and rows their permissions allow, without sharing a single broad execution role. With TIP, enterprises get per-user data boundaries enforced based on who is running the query, full audit attribution with CloudTrail recording which user accessed data, and reduced admin friction since identity propagates automatically through the existing compute connection with no extra login, token, or role management required.

To get started, use a notebook in a TIP enabled Project with the supported engines. This feature is available in [all AWS Regions where Amazon SageMaker Unified Studio is available](https://docs.aws.amazon.com/sagemaker-unified-studio/latest/adminguide/supported-regions.html). To learn more, see [Trusted identity propagation](https://docs.aws.amazon.com/sagemaker-unified-studio/latest/adminguide/trusted-identity-propagation.html) in the Amazon SageMaker Unified Studio Administrator Guide and [Notebooks](https://docs.aws.amazon.com/sagemaker-unified-studio/latest/userguide/notebooks.html) in the Amazon SageMaker Unified Studio User Guide.
