---
title: Sign up for AWS (new): projects, credits, and when advanced still wins
description: On 16 Sep 2026 AWS opened Sign up (new) with $100 in credits at signup, up to $200 over 6 months, and a project pinned to one of three Regions. Use advanced on day one for HIPAA, Marketplace, or a Region you choose.
url: https://www.factualminds.com/blog/sign-up-for-aws-new-guide-2026/
datePublished: 2026-10-01T00:00:00.000Z
dateModified: 2026-10-01T00:00:00.000Z
author: palaniappan-p
category: Cloud Architecture
tags: aws-account, aws-iam, aws-organizations, aws-free-tier
---

# Sign up for AWS (new): projects, credits, and when advanced still wins

> On 16 Sep 2026 AWS opened Sign up (new) with $100 in credits at signup, up to $200 over 6 months, and a project pinned to one of three Regions. Use advanced on day one for HIPAA, Marketplace, or a Region you choose.

On **16 September 2026**, AWS published a signup path for a new project, separate from the account a team uses when it already needs to choose a Region and own its policies. [Micah Walter's news post](https://aws.amazon.com/blogs/aws/aws-reimagines-the-getting-started-experience/) describes the simplified experience. The Account Management guide names the two choices [Sign up for AWS (new)](https://docs.aws.amazon.com/accounts/latest/reference/sign-in-new.html) and [Sign up for AWS (advanced)](https://docs.aws.amazon.com/accounts/latest/reference/getting-started.html). The compare page, the signup page, and the regions page each still carried the same warning as read **1 October 2026**: this experience is releasing to a limited number of customers, and you might not have it yet.

FactualMinds has not completed a signup on this rollout. The figures below are those pages, read **1 October 2026**, plus the 16 September news post and the [What's New note](https://aws.amazon.com/about-aws/whats-new/2026/09/New-AWS-Builder-Experience/) from the same day. They are not a balance from an account we opened.

> **Reproduce this** — Copy [`signup-path-worksheet.csv`](/examples/architecture-blog-2026/aws-getting-started-signup/signup-path-worksheet.csv) and fill the last row before you click **Create account**. The earlier rows are decision rules from the AWS compare page, not a customer account.

## Pick the path before the account exists

Sign up (new) fits a first project that can live in the Region AWS assigns, on the services that path allows, with every invited person as an administrator of that project. Sign up (advanced) is the account where you choose the Region, you write the organization policies, and you can designate the account for HIPAA or FedRAMP.

**Opinion:** Use Sign up (new) when none of the worksheet's advanced rows apply to this workload. Use advanced on day one when any advanced row applies. The 16 September news post says you can activate advanced features later, at no additional cost, with no migration and no downtime. The [activation page](https://docs.aws.amazon.com/accounts/latest/reference/activate-advanced-features.html), read 1 October 2026, says you must already be on a paid plan, and activation cannot be reversed. When you already know you need the withheld controls, start on advanced.

The trade-off of starting advanced is the first hour the new path was built to skip: you configure the account yourself. The [compare page](https://docs.aws.amazon.com/accounts/latest/reference/sign-up-for-aws.html) marks project spend limits and the local-agent connect script as features of Sign up (new). The trade-off of starting new is one assigned Region, organization policies AWS manages, and a service list that removes cross-Region features even from services it includes.

Walter's post says builders do not want to spend the first hours configuring an environment. They want to build what they came to build. That shortcut is real for a sandbox. It is the wrong shortcut for a workload you already know is regulated, multi-Region, or locked to a Region.

### What the compare page withholds

| Feature | Sign up (new) | Sign up (advanced) |
| --- | --- | --- |
| Partner Network, Enterprise Agreement, extra AWS Activate credits | No | Yes |
| AWS Marketplace | No. Supported-services says "Bedrock and Free only" | Yes |
| HIPAA or SEC designation | No | Yes |
| Choose the Region, or use an opt-in Region | No | Yes |
| IAM Access Analyzer and sign-in access policies | No | Yes |
| Service control policies you write | No. AWS manages them | Yes |
| Project spend limits | Yes | No |
| Script to connect a local coding agent | Yes | No |
| Savings Plans | No | Yes |
| Organizations and IAM Identity Center | Automatic, and AWS manages them | You set them up |

The compare page also withholds a Professional Services contract, an AWS Skill Builder team subscription, work with an AWS Training Partner, and net-terms billing. Its rule for anything absent from that table, and absent from the access-management section, is that the feature is available. Hold that rule up against the [supported-services page](https://docs.aws.amazon.com/accounts/latest/reference/supported-services-sign-up-new.html). A service on the "not supported unless you activate advanced features" list is still blocked, even if the compare table never names it.

## The Region is assigned from your address

When the project is created, AWS assigns one of three Regions from the country on the contact address. The [regions page](https://docs.aws.amazon.com/accounts/latest/reference/project-regions.html) dates those country tables **18 August 2026**:

| If the contact address is in | The project is in |
| --- | --- |
| The United States or Canada | US East (Ohio), `us-east-2` |
| The United Kingdom | Europe (Stockholm), `eu-north-1` |
| India | Asia Pacific (Sydney), `ap-southeast-2` |

A United States address lands in Ohio, not in N. Virginia. An India address lands in Sydney, not in Mumbai. The page has the full country lists. Changing the address in AWS Settings later does not move the Region. Additional Regions, if AWS adds them, apply to new sign-ups. An existing project stays where it was created. If you need a specific Region, or an opt-in Region, that page says to use advanced signup, or to activate advanced features.

Two placements on the same page sit outside the project Region. AWS WAF and Amazon CloudWatch Logs are available in US East (N. Virginia), `us-east-1`. CloudFront features that would create resources outside your selected Region are unavailable, including AWS WAF attached to CloudFront. Bedrock APIs that do not create resources can run in commercial Regions that are enabled by default. Global and geographic cross-Region inference are on the unsupported-feature list for this signup.

Before you create a resource, open [AWS Settings](https://settings.aws.com), choose Project, then Additional Info, and read the Region. The project account ID is on that same panel.

## What a project is, and who can open it

A project contains an AWS account and the settings for sharing it. The projects you own make up an organization, which you reach through the management account in AWS Settings. That organization is an AWS Organization whose policies AWS manages, including service control policies and resource control policies. You do not create a root user.

You invite a person by email. That person receives administrator access to the projects you name, and only those. You can create IAM users and IAM roles. They work for programmatic access, not for console access. There is no human read-only role in this default.

Inside one project, code can reach the other resources in that project without extra permission setup. A resource in a different project cannot, unless you turn on cross-project access. The compare page's example is a Lambda function in one project called by an API in another, and only when both projects belong to the same management account. Nothing is public until you open it: a public S3 bucket, an API Gateway API, an EC2 instance with a public IP, a CloudFront distribution, or a Lambda function URL.

That default is why Walter's demo did not hand-configure resource permissions. It is also why this path is the wrong place for a team that needs a break-glass role or a policy it wrote. The compare page says it directly: if you need fine-grained control over users or role-based permissions, do not use Sign up (new).

## How the signup runs

The [signup page](https://docs.aws.amazon.com/accounts/latest/reference/sign-in-new.html) is the procedure. The button label matters. On the banner that explains the two paths, the new path is labeled **Sign up for AWS**. Advanced is the other choice on that banner. Looking for the word "new" on the button will send you past it.

1. Go to [aws.amazon.com](https://aws.amazon.com/) and choose **Create account**.
2. On the banner, choose **Sign up for AWS**.
3. Sign in with Google, GitHub, Apple, or Amazon. If a Google account is already signed in in that browser, AWS uses it.
4. Enter the name teammates will see, verify the email with the code AWS sends, and set a password.
5. Enter the contact details. The country on that form is what assigns the Region.
6. AWS provisions the first project in one of the three Regions and gives it a name. You can rename it.

AWS also creates an AWS Builder ID for that email. One Builder ID exists per email address. If you already have a Builder ID and no AWS account, some settings may already be filled in, and you change them afterward.

The password must be 8 to 128 characters. It must include at least three of uppercase, lowercase, numbers, and symbols. It must not match the account name or the email. The symbol set on the page includes the usual punctuation plus angle brackets, square brackets, and braces.

AWS may still ask for a payment method. Verification can place a hold of **USD $1**, or the local equivalent, for **3 to 5 days**. The page says you will not incur charges until you upgrade to a paid plan. You can change the payment method or close the account in AWS Settings. If you are ineligible for the Free Tier, you provide payment information and AWS places you on the Paid Plan. On that plan you can set a spend limit.

## Credits, and the clock that closes the account

Keep the credit figures attached to the page that published them.

The [Free Tier page](https://aws.amazon.com/free/), as read **1 October 2026**, gives a new customer **$100** in credits immediately and up to **$100** more for activities. That is up to **$200** across **6 months**. The same page says the free plan covers "over 90" services, that you are not charged unless you convert to a paid plan, and that promotional credits are not available on the free plan. The 16 September What's New post says "up to $200 in free credits," which matches that ceiling.

The same day's [news post](https://aws.amazon.com/blogs/aws/aws-reimagines-the-getting-started-experience/) shows **$100** at signup. In Walter's walkthrough, deploying a Lambda added **$20**. Treat the $20 as his demo. It is not a line on the Free Tier page. His API was Lambda, DynamoDB, and API Gateway, which are on the free-tier service list for this experience. He pasted a console prompt, and the agent installed the AWS CLI and the Agent Toolkit for AWS and wrote a `CLAUDE.md`. He wrote that a Google sign-in left him with a project within seconds. That timing is his report.

The account-level list, once you are on Sign up (new), is the [supported-services page](https://docs.aws.amazon.com/accounts/latest/reference/supported-services-sign-up-new.html). It is a long allow-list, and it still removes cross-Region features from services it includes. On the free-tier portion, as read 1 October 2026, the removals include:

- S3 Cross-Region Replication and Multi-Region Access Points
- DynamoDB global tables
- Lambda@Edge, including Lambda@Edge on CloudFront
- RDS cross-Region read replicas and Aurora Global Databases
- KMS multi-Region keys
- Cross-Region VPC peering
- SES global endpoints
- CloudFormation StackSets
- Multi-Region CloudTrail trails and organization trails
- Bedrock global and geographic cross-Region inference

A paid plan on this same signup adds another list, including Amazon Kinesis, Amazon Redshift, Amazon EMR, Amazon MSK, Amazon DocumentDB, and Amazon Neptune, still with cross-Region features marked unsupported. Several names on that paid list are also marked unavailable in Europe (Stockholm), among them Amazon Textract, Amazon Personalize, and Amazon Kinesis Video Streams. Stockholm is where a United Kingdom address lands. Amazon Managed Blockchain is on the paid list and marked unavailable in all three assigned Regions: Stockholm, Ohio, and Sydney. Check the country and the service together.

### The free plan closes the account

The Free Tier page says the account closes on its own **6 months** after you open it, or when the credits run out, whichever comes first. That is not a pause you resume by raising a ceiling. If the workload has to exist next quarter, move to a paid plan before that clock. A spend-limit pause, which exists only after you are on a paid plan, is a different control: leave a paused project alone for **90 days** and AWS deletes the project data. That behavior is in [A spend limit that pauses the project](/blog/aws-settings-project-spend-limits-2026/).

### A paid plan is not advanced signup

The [upgrade page](https://docs.aws.amazon.com/accounts/latest/reference/upgrade-account.html) says upgrading does not turn the account into Sign up (advanced). Features that exist only on an advanced account stay unavailable after the upgrade. You still have to activate advanced features.

Until you do, the supported-services page blocks a set of services it describes as unnecessary for new developers or small teams, and it notes that some of them are turned on and managed by AWS. The names that change the signup decision include Amazon GuardDuty, AWS Security Hub, Amazon Macie, AWS Control Tower, AWS Transit Gateway, AWS Direct Connect, Amazon FSx, AWS Shield, AWS Trusted Advisor, IAM Access Analyzer, AWS Database Migration Service, and Amazon Q Developer. AWS Artifact on the free list excludes the HIPAA Business Associate Addendum and the SEC Rule 17a-4 and 18a-6 addenda.

The compare page says you cannot use AWS Marketplace on Sign up (new). The supported-services page lists Marketplace with the note "Bedrock and Free only." Read that as a narrow exception. A Marketplace AMI, SaaS contract, or container is an advanced-signup requirement.

## The agent prompt, and where it stops

After signup, the news post shows a prompt you paste into a coding agent. In Walter's walkthrough the agent installed the CLI and the Agent Toolkit, signed in, and wrote `CLAUDE.md`. The compare page lists "Set up script to connect your local agent to your AWS accounts" as **Yes** on Sign up (new) and **No** on advanced.

Advanced signup has its own first hour, on the [advanced getting-started page](https://docs.aws.amazon.com/accounts/latest/reference/getting-started.html). Install the AWS CLI at version **2.32.0** or later, then set up the AWS MCP Server. Agents authenticate API calls with IAM credentials you already have. Documentation search on that server does not require credentials. That is a different start from a pasted prompt.

Paste the prompt when you chose Sign up (new) and you want the agent deploying into the project AWS created. The skill catalog is a separate guide: [AWS Agent Toolkit for AWS: Plugins, Rules, and Every Skill Explained](/blog/aws-agent-toolkit-for-aws-skills-guide/). We did not run Walter's sequential-ID API. This post does not treat his endpoint, his timing, or his extra $20 as our result.

## Spend limits can pause the project

The compare page lists project spend limits as **Yes** on Sign up (new) and **No** on advanced signup. The news post says you can set a monthly ceiling from **$20**, you pay what you use up to that ceiling, and AWS pauses the project when spend reaches it. Its example is a **$50** ceiling and **$32** of charges: you pay $32, plus tax.

The operational detail is stricter than that paragraph, and it is already written. The [spend-limits guide](/blog/aws-settings-project-spend-limits-2026/) covers alerts at **50%**, **75%**, and **90%**, the optional actions that stop or delete resources days before the ceiling, and the **90-day** deletion if you leave the pause alone. The minimum there is the greater of $20 or AWS's estimate. Credits do not count toward the ceiling. Read that guide before you put a limit on anything you cannot pause. Leave it off a storefront.

## Activating advanced features is one way

When the withheld services become the requirement, activation is a separate action from the paid-plan upgrade.

You must already be on a paid plan. In AWS Settings, open Projects, choose Actions, then **Explore advanced features**. The page says activation cannot be reversed, so it inserts time to read before you commit. You enter a team name. That name is the IAM Identity Center instance your workforce will see. You choose a management-account email for tasks that need root-level permissions, verify it, and confirm. If that email differs from your Builder ID, the Builder ID can still reach the management account from AWS Settings, as long as Builder ID remains the identity source.

What you take over is complete control of the AWS Organization, the management account, and the delegated administrator account that were managing your projects and the people you invited. You then manage security, governance, and membership yourself, and you gain the additional services and multi-Region capabilities.

The 16 September news post describes that moment as an organization already built, at no additional cost, with no migration and no downtime. The activation page we read does not restate a price or a downtime number. We have not activated it. "No downtime" is AWS's claim from that post. "Cannot be reversed" is the control on the page.

Control Tower for accounts you already operate is a different job, and Control Tower is on the unsupported list for Sign up (new). Start from [How to Set Up AWS Control Tower for Multi-Account Governance](/blog/how-to-set-up-aws-control-tower-multi-account-governance/) on an advanced account.

## What to Do This Week

1. Copy the worksheet and mark which rows apply to the workload this account will hold. Mark them for this account, not for the company in general.
2. If any row says advanced, use **Sign up for AWS (advanced)**. A later activation is the wrong sequence for HIPAA, a Marketplace purchase, a Region you must choose, or policies you intend to write.
3. If no advanced row applies, go to aws.amazon.com, choose **Create account**, and on the banner choose **Sign up for AWS**. If the banner is missing, the rollout has not reached you. Use advanced when you need the account today.
4. Before the first resource, open settings.aws.com and read the Region. A United States address is Ohio. An India address is Sydney. A United Kingdom address is Stockholm.
5. If the agent prompt is why you are here, paste it on this project, and read the toolkit guide before the agent leaves a sandbox.
6. If you will outlive the credits, move to a paid plan before the 6-month close, and read the spend-limit guide before you set a ceiling.

## What This Post Doesn't Cover

- A signup, a credit balance, or an activation we ran. The limited-rollout warning was still on the docs on 1 October 2026.
- Every service on the allow-list, and every country in the Region tables. Both will move. Use the [supported-services page](https://docs.aws.amazon.com/accounts/latest/reference/supported-services-sign-up-new.html) and the [regions page](https://docs.aws.amazon.com/accounts/latest/reference/project-regions.html), whose tables are dated 18 August 2026.
- Which pause action deletes a fine-tuned model. That is the [spend-limits guide](/blog/aws-settings-project-spend-limits-2026/).
- How to design a Control Tower landing zone for an organization you already run.
- The Agent Toolkit skill catalog, and whether Walter's sequential-ID API is a pattern to copy.
- A price or a downtime measurement for activation beyond the wording of the 16 September news post.

## FAQ

### When should I not use Sign up for AWS (new)?
Use Sign up for AWS (advanced) on day one when the workload needs HIPAA, FedRAMP, an SEC designation, a Marketplace purchase, the Partner Network, an Enterprise Agreement, net-terms billing, a Region you choose, an opt-in Region, your own service control policies, or fine-grained human roles. GuardDuty, Security Hub, Macie, Control Tower, Transit Gateway, Direct Connect, and Amazon Q Developer are on the unsupported list until you activate advanced features. Activation requires a paid plan first, and it cannot be reversed.

### What goes wrong if I need AWS Marketplace or a HIPAA agreement?
The compare page marks Marketplace and a HIPAA or SEC designation as unavailable on Sign up (new). The supported-services page lists Marketplace as Bedrock and Free only, and it excludes the HIPAA Business Associate Addendum and the SEC addenda on AWS Artifact. Upgrading to a paid plan does not turn those on. You either sign up advanced from the start, or you activate advanced features later, which cannot be undone.

### Is the credit $100 or $200?
The Free Tier page, as read 1 October 2026, gives $100 immediately and up to $100 more from activities, so up to $200 over 6 months. The 16 September 2026 What's New post says up to $200, which matches that ceiling. The same day's news post shows $100 at signup. Micah Walter reported an extra $20 when his demo Lambda deployed. That $20 is his walkthrough, not a line on the Free Tier page. The free plan ends at 6 months or when the credits run out, whichever comes first, and the account closes.

### Does the $1 hold mean I will be billed?
The signup page says verification may hold USD $1, or the local equivalent, for 3 to 5 days. You do not incur charges until you upgrade to a paid plan. If you are ineligible for the Free Tier, you must provide a payment method and AWS places you on the Paid Plan, where you can set a spend limit.

### What if I cannot see the new signup?
The compare page, the signup page, and the regions page each still warned, as read 1 October 2026, that this experience is releasing to a limited number of customers and you might not have it yet. If Create account does not show the banner, use Sign up for AWS (advanced) when you need the account today.

### Can I create IAM users and a root password on the new path?
You do not create a root user. People you invite by email receive administrator access to the projects you name. You can create IAM users and roles for programmatic access only, not for the console. AWS manages the organization policies. If you need a human read-only role or a policy you wrote, use advanced signup.

---

*Source: https://www.factualminds.com/blog/sign-up-for-aws-new-guide-2026/*
