Some configuration enhancements may require you to update the CloudFormation stack template.
For example, in October 2025, access control changes to Lambda function URLs interrupted the ability of the Arctic Wolf® generic firewall denylist Active Response integration to access the denylist stored in your Simple Storage Service (S3) bucket, through the Arctic Wolf CloudFormation stack template. Customers who completed Configure Generic Firewall Denylist for Arctic Wolf Active Response before February 2026 must replace their existing CloudFormation template with the latest version available in the Arctic Wolf Unified Portal. For more information, see Control access to Lambda function URLs.
- Sign in to the Arctic Wolf Unified Portal.
- In the navigation menu, click .
- In the Active Response section, click Download CloudFormation Template.
This CloudFormation template contains all required resources for Arctic Wolf to update the generic firewall integration denylist.
The deny_list_cfn zip file automatically downloads to your Downloads folder.
- Navigate to your Downloads folder, and then extract the contents of the deny_list_cfn zip file.
- Sign in to the AWS CloudFormation console.
- On the Stacks page, filter for the stack that you want to update. For examplecreated in Configure Generic Firewall Denylist for Arctic Wolf Active Response. For example
firewall-deny-list.
- Click the stack name.
- Click .
- On the Create change set page, select these options:
-
Change set type section — Standard change set
-
Prerequisite - Prepare template section — Replace existing template
-
Specify template section — Upload a template file
- Click Choose file and select the extracted contents of the deny_list_cfn zip file.
- Click Next.
- On the Specify change set details page, click Next.
Note: Do not adjust settings on the Specify change set details page, unless your Concierge Security® Team (CST) requests it.
- On the Configure change set options page, check the I acknowledge that AWS CloudFormation might create IAM resources checkbox, and then click Next.
Note: Do not adjust any other settings on the Configure change set options page, unless your CST requests it.
- On the Review change set page, review the change set and click Create change set.
The change set details page opens. The change set status is CREATE_PENDING.
- When the status changes to CREATE_COMPLETE, click Execute change set.
- In the Execute change set? confirmation dialog, keep the default settings, and then click Execute change set.
The Events tab opens. The change set status is UPDATE_IN_PROGRESS. When the status changes to UPDATE_COMPLETE, your CloudFormation stack template is updated.
- Optional: If you are updating the CloudFormation stack template because ofaccess control changes for Lambda function URLs, validate that the template update was successful:
- Click the Resources tab.
- In the table, find the entry with a Logical ID value of GetDenyList, and then click the corresponding Physical ID link.
- In the console, click the Configuration tab.
- In the Function URL section, verify that this message appears:
Your function URL is public. Anyone with the URL can access your function.
- Contact your CST to inform them that you completed this process.