AWS Config launches 13 new managed rules

Posted on: Jan 22, 2026

AWS Config announces launch of an additional 13 managed Config rules for various use cases such as security, durability, and operations. You can now search, discover, enable and manage these additional rules directly from AWS Config and govern more use cases for your AWS environment.

With this launch, you can now enable these controls across your account or across your organization. For example, you can assess your security posture across Amazon Cognito User pools, Amazon EBS Snapshots, AWS Cloudformation Stacks and more. Additionally, you can leverage Conformance Packs to group these new controls and deploy across an account or across organization, streamlining your multi-account governance.

For the full list of recently released rules, visit the AWS Config developer guide. For description of each rule and the AWS Regions in which it is available, please refer our Config managed rules documentation. To start using Config rules, please refer our documentation.

New Rules Launched:

  1. AURORA_GLOBAL_DATABASE_ENCRYPTION_AT_REST
  2. CLOUDFORMATION_STACK_SERVICE_ROLE_CHECK
  3. CLOUDFORMATION_TERMINATION_PROTECTION_CHECK
  4. CLOUDFRONT_DISTRIBUTION_KEY_GROUP_ENABLED
  5. COGNITO_USER_POOL_DELETE_PROTECTION_ENABLED
  6. COGNITO_USER_POOL_MFA_ENABLED
  7. COGNITO_USERPOOL_CUST_AUTH_THREAT_FULL_CHECK
  8. EBS_SNAPSHOT_BLOCK_PUBLIC_ACCESS
  9. ECS_CAPACITY_PROVIDER_TERMINATION_CHECK
  10. ECS_TASK_DEFINITION_EFS_ENCRYPTION_ENABLED
  11. ECS_TASK_DEFINITION_LINUX_USER_NON_ROOT
  12. ECS_TASK_DEFINITION_WINDOWS_USER_NON_ADMIN
  13. SES_SENDING_TLS_REQUIRED