- Introduces outbound IAM identity federation in the AWS European Sovereign Cloud (Germany) region, letting workloads exchange IAM credentials for short‑lived JWTs to access external services.
- Provides fine‑grained access control and compliance by allowing token properties (lifetime, audience, signing algorithm) to be managed via IAM policies and audited with CloudTrail.
- Enables secure authentication to third‑party cloud providers, SaaS platforms, and self‑hosted applications without using long‑term credentials.