

# Actions, resources, and condition keys for AWS Identity and Access Management (IAM)
<a name="list_awsidentityandaccessmanagementiam"></a>

AWS Identity and Access Management (IAM) (service prefix: `iam`) provides the following service-specific resources, actions, and condition context keys for use in IAM permission policies.

References:
+ Learn how to [configure this service](https://docs.aws.amazon.com/IAM/latest/UserGuide/introduction.html).
+ View a list of the [API operations available for this service](https://docs.aws.amazon.com/IAM/latest/APIReference/).
+ Learn how to secure this service and its resources by [using IAM](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html) permission policies.

**Topics**
+ [Actions defined by AWS Identity and Access Management (IAM)](#awsidentityandaccessmanagementiam-actions-as-permissions)
+ [Resource types defined by AWS Identity and Access Management (IAM)](#awsidentityandaccessmanagementiam-resources-for-iam-policies)
+ [Condition keys for AWS Identity and Access Management (IAM)](#awsidentityandaccessmanagementiam-policy-keys)

## Actions defined by AWS Identity and Access Management (IAM)
<a name="awsidentityandaccessmanagementiam-actions-as-permissions"></a>

You can specify the following actions in the `Action` element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

The **Access level** column of the Actions table describes how the action is classified (List, Read, Permissions management, or Tagging). This classification can help you understand the level of access that an action grants when you use it in a policy. For more information about access levels, see [Access levels in policy summaries](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_understand-policy-summary-access-level-summaries.html).

The **Resource types** column of the Actions table indicates whether each action supports resource-level permissions. If there is no value for this column, you must specify all resources ("\*") to which the policy applies in the `Resource` element of your policy statement. If the column includes a resource type, then you can specify an ARN of that type in a statement with that action. If the action has one or more required resources, the caller must have permission to use the action with those resources. Required resources are indicated in the table with an asterisk (\*). If you limit resource access with the `Resource` element in an IAM policy, you must include an ARN or pattern for each required resource type. Some actions support multiple resource types. If the resource type is optional (not indicated as required), then you can choose to use one of the optional resource types.

The **Condition keys** column of the Actions table includes keys that you can specify in a policy statement's `Condition` element. For more information on the condition keys that are associated with resources for the service, see the **Condition keys** column of the Resource types table.

The **Dependent actions** column of the Actions table shows additional permissions that may be required to successfully call an action. These permissions may be needed in addition to the permission for the action itself. When an action specifies dependent actions, those dependencies may apply to additional resources defined for that action, not only the first resource listed in the table.

**Note**  
Resource condition keys are listed in the [Resource types](#awsidentityandaccessmanagementiam-resources-for-iam-policies) table. You can find a link to the resource type that applies to an action in the **Resource types (\*required)** column of the Actions table. The resource type in the Resource types table includes the **Condition keys** column, which are the resource condition keys that apply to an action in the Actions table.

For details about the columns in the following table, see [Actions table](reference_policies_actions-resources-contextkeys.html#actions_table).


****  


- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_AcceptDelegationRequest.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_AcceptDelegationRequest.html) **
  - **Description:** Accepts a delegation request resource, granting the requested temporary access
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-delegation-request](#awsidentityandaccessmanagementiam-delegation-request) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_AddClientIDToOpenIDConnectProvider.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_AddClientIDToOpenIDConnectProvider.html) **
  - **Description:** Grants permission to add a new client ID (audience) to the list of registered IDs for the specified IAM OpenID Connect (OIDC) provider resource
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-oidc-provider](#awsidentityandaccessmanagementiam-oidc-provider) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_AddRoleToInstanceProfile.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_AddRoleToInstanceProfile.html) **
  - **Description:** Grants permission to add an IAM role to the specified instance profile
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-instance-profile](#awsidentityandaccessmanagementiam-instance-profile) 
  - **Condition keys:** 
  - **Dependent actions:**  iam:PassRole 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_AddUserToGroup.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_AddUserToGroup.html) **
  - **Description:** Grants permission to add an IAM user to the specified IAM group
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-group](#awsidentityandaccessmanagementiam-group) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_AssociateDelegationRequest.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_AssociateDelegationRequest.html) **
  - **Description:** Associates a delegation request resource with the calling identity
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-delegation-request](#awsidentityandaccessmanagementiam-delegation-request) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_AttachGroupPolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_AttachGroupPolicy.html) **
  - **Description:** Grants permission to attach a managed policy to the specified IAM group
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-group](#awsidentityandaccessmanagementiam-group)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_PolicyARN](#awsidentityandaccessmanagementiam-iam_PolicyARN)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_AttachRolePolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_AttachRolePolicy.html) **
  - **Description:** Grants permission to attach a managed policy to the specified IAM role
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_PolicyARN](#awsidentityandaccessmanagementiam-iam_PolicyARN) <br /> [#awsidentityandaccessmanagementiam-iam_PermissionsBoundary](#awsidentityandaccessmanagementiam-iam_PermissionsBoundary)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_AttachUserPolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_AttachUserPolicy.html) **
  - **Description:** Grants permission to attach a managed policy to the specified IAM user
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_PolicyARN](#awsidentityandaccessmanagementiam-iam_PolicyARN) <br /> [#awsidentityandaccessmanagementiam-iam_PermissionsBoundary](#awsidentityandaccessmanagementiam-iam_PermissionsBoundary)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ChangePassword.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ChangePassword.html) **
  - **Description:** Grants permission to an IAM user to change their own password
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateAccessKey.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateAccessKey.html) **
  - **Description:** Grants permission to create access key and secret access key for the specified IAM user
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateAccountAlias.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateAccountAlias.html) **
  - **Description:** Grants permission to create an alias for your AWS account
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateDelegationRequest.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateDelegationRequest.html) **
  - **Description:** Creates an IAM delegation request resource for temporary access delegation
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-delegation-request](#awsidentityandaccessmanagementiam-delegation-request)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_DelegationDuration](#awsidentityandaccessmanagementiam-iam_DelegationDuration) <br /> [#awsidentityandaccessmanagementiam-iam_NotificationChannel](#awsidentityandaccessmanagementiam-iam_NotificationChannel) <br /> [#awsidentityandaccessmanagementiam-iam_TemplateArn](#awsidentityandaccessmanagementiam-iam_TemplateArn)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateGroup.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateGroup.html) **
  - **Description:** Grants permission to create a new group
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-group](#awsidentityandaccessmanagementiam-group) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateInstanceProfile.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateInstanceProfile.html) **
  - **Description:** Grants permission to create a new instance profile
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-instance-profile](#awsidentityandaccessmanagementiam-instance-profile)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys) <br /> [#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_](#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateLoginProfile.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateLoginProfile.html) **
  - **Description:** Grants permission to create a password for the specified IAM user
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateOpenIDConnectProvider.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateOpenIDConnectProvider.html) **
  - **Description:** Grants permission to create an IAM resource that describes an identity provider (IdP) that supports OpenID Connect (OIDC)
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-oidc-provider](#awsidentityandaccessmanagementiam-oidc-provider)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys) <br /> [#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_](#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreatePolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreatePolicy.html) **
  - **Description:** Grants permission to create a new managed policy
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-policy](#awsidentityandaccessmanagementiam-policy)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys) <br /> [#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_](#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreatePolicyVersion.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreatePolicyVersion.html) **
  - **Description:** Grants permission to create a new version of the specified managed policy
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-policy](#awsidentityandaccessmanagementiam-policy) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateRole.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateRole.html) **
  - **Description:** Grants permission to create a new role
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_PermissionsBoundary](#awsidentityandaccessmanagementiam-iam_PermissionsBoundary) <br /> [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys) <br /> [#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_](#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateSAMLProvider.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateSAMLProvider.html) **
  - **Description:** Grants permission to create an IAM resource that describes an identity provider (IdP) that supports SAML 2.0
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-saml-provider](#awsidentityandaccessmanagementiam-saml-provider)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys) <br /> [#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_](#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateServiceLinkedRole.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateServiceLinkedRole.html) **
  - **Description:** Grants permission to create an IAM role that allows an AWS service to perform actions on your behalf
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_AWSServiceName](#awsidentityandaccessmanagementiam-iam_AWSServiceName)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateServiceSpecificCredential.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateServiceSpecificCredential.html) **
  - **Description:** Grants permission to create a new service-specific credential for an IAM user
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_ServiceSpecificCredentialAgeDays](#awsidentityandaccessmanagementiam-iam_ServiceSpecificCredentialAgeDays) <br /> [#awsidentityandaccessmanagementiam-iam_ServiceSpecificCredentialServiceName](#awsidentityandaccessmanagementiam-iam_ServiceSpecificCredentialServiceName)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateUser.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateUser.html) **
  - **Description:** Grants permission to create a new IAM user
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_PermissionsBoundary](#awsidentityandaccessmanagementiam-iam_PermissionsBoundary) <br /> [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys) <br /> [#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_](#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateVirtualMFADevice.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateVirtualMFADevice.html) **
  - **Description:** Grants permission to create a new virtual MFA device
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-mfa](#awsidentityandaccessmanagementiam-mfa)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys) <br /> [#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_](#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeactivateMFADevice.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeactivateMFADevice.html) **
  - **Description:** Grants permission to deactivate the specified MFA device and remove its association with the IAM user for which it was originally enabled
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteAccessKey.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteAccessKey.html) **
  - **Description:** Grants permission to delete the access key pair that is associated with the specified IAM user
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteAccountAlias.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteAccountAlias.html) **
  - **Description:** Grants permission to delete the specified AWS account alias
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteAccountPasswordPolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteAccountPasswordPolicy.html) **
  - **Description:** Grants permission to delete the password policy for the AWS account
  - **Access level:** Permissions management
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/private-content-trusted-signers.html](https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/private-content-trusted-signers.html) **
  - **Description:** Grants permission to delete an existing CloudFront public key
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteGroup.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteGroup.html) **
  - **Description:** Grants permission to delete the specified IAM group
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-group](#awsidentityandaccessmanagementiam-group) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteGroupPolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteGroupPolicy.html) **
  - **Description:** Grants permission to delete the specified inline policy from its group
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-group](#awsidentityandaccessmanagementiam-group) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteInstanceProfile.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteInstanceProfile.html) **
  - **Description:** Grants permission to delete the specified instance profile
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-instance-profile](#awsidentityandaccessmanagementiam-instance-profile) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteLoginProfile.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteLoginProfile.html) **
  - **Description:** Grants permission to delete the password for the specified IAM user
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteOpenIDConnectProvider.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteOpenIDConnectProvider.html) **
  - **Description:** Grants permission to delete an OpenID Connect identity provider (IdP) resource object in IAM
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-oidc-provider](#awsidentityandaccessmanagementiam-oidc-provider) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeletePolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeletePolicy.html) **
  - **Description:** Grants permission to delete the specified managed policy and remove it from any IAM entities (users, groups, or roles) to which it is attached
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-policy](#awsidentityandaccessmanagementiam-policy) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeletePolicyVersion.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeletePolicyVersion.html) **
  - **Description:** Grants permission to delete a version from the specified managed policy
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-policy](#awsidentityandaccessmanagementiam-policy) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteRole.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteRole.html) **
  - **Description:** Grants permission to delete the specified role
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_PermissionsBoundary](#awsidentityandaccessmanagementiam-iam_PermissionsBoundary)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteRolePermissionsBoundary.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteRolePermissionsBoundary.html) **
  - **Description:** Grants permission to remove the permissions boundary from a role
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_PermissionsBoundary](#awsidentityandaccessmanagementiam-iam_PermissionsBoundary)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteRolePolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteRolePolicy.html) **
  - **Description:** Grants permission to delete the specified inline policy from the specified role
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_PermissionsBoundary](#awsidentityandaccessmanagementiam-iam_PermissionsBoundary)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteSAMLProvider.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteSAMLProvider.html) **
  - **Description:** Grants permission to delete a SAML provider resource in IAM
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-saml-provider](#awsidentityandaccessmanagementiam-saml-provider) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteSSHPublicKey.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteSSHPublicKey.html) **
  - **Description:** Grants permission to delete the specified SSH public key
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteServerCertificate.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteServerCertificate.html) **
  - **Description:** Grants permission to delete the specified server certificate
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-server-certificate](#awsidentityandaccessmanagementiam-server-certificate) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteServiceLinkedRole.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteServiceLinkedRole.html) **
  - **Description:** Grants permission to delete an IAM role that is linked to a specific AWS service, if the service is no longer using it
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteServiceSpecificCredential.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteServiceSpecificCredential.html) **
  - **Description:** Grants permission to delete the specified service-specific credential for an IAM user
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_ServiceSpecificCredentialServiceName](#awsidentityandaccessmanagementiam-iam_ServiceSpecificCredentialServiceName)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteSigningCertificate.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteSigningCertificate.html) **
  - **Description:** Grants permission to delete a signing certificate that is associated with the specified IAM user
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteUser.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteUser.html) **
  - **Description:** Grants permission to delete the specified IAM user
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteUserPermissionsBoundary.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteUserPermissionsBoundary.html) **
  - **Description:** Grants permission to remove the permissions boundary from the specified IAM user
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_PermissionsBoundary](#awsidentityandaccessmanagementiam-iam_PermissionsBoundary)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteUserPolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteUserPolicy.html) **
  - **Description:** Grants permission to delete the specified inline policy from an IAM user
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_PermissionsBoundary](#awsidentityandaccessmanagementiam-iam_PermissionsBoundary)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteVirtualMFADevice.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteVirtualMFADevice.html) **
  - **Description:** Grants permission to delete a virtual MFA device
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-mfa](#awsidentityandaccessmanagementiam-mfa)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-sms-mfa](#awsidentityandaccessmanagementiam-sms-mfa)  / **Condition keys:**  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DetachGroupPolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DetachGroupPolicy.html) **
  - **Description:** Grants permission to detach a managed policy from the specified IAM group
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-group](#awsidentityandaccessmanagementiam-group)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_PolicyARN](#awsidentityandaccessmanagementiam-iam_PolicyARN)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DetachRolePolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DetachRolePolicy.html) **
  - **Description:** Grants permission to detach a managed policy from the specified role
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_PolicyARN](#awsidentityandaccessmanagementiam-iam_PolicyARN) <br /> [#awsidentityandaccessmanagementiam-iam_PermissionsBoundary](#awsidentityandaccessmanagementiam-iam_PermissionsBoundary)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DetachUserPolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DetachUserPolicy.html) **
  - **Description:** Grants permission to detach a managed policy from the specified IAM user
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_PolicyARN](#awsidentityandaccessmanagementiam-iam_PolicyARN) <br /> [#awsidentityandaccessmanagementiam-iam_PermissionsBoundary](#awsidentityandaccessmanagementiam-iam_PermissionsBoundary)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DisableOrganizationsRootCredentialsManagement.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DisableOrganizationsRootCredentialsManagement.html) **
  - **Description:** Grants permission to disable the management of member account root user credentials for an organization managed under the current account
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_DisableOrganizationsRootSessions.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_DisableOrganizationsRootSessions.html) **
  - **Description:** Grants permission to disable privileged root actions in member accounts for an organization managed under the current account
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_AddClientIDToOpenIDConnectProvider.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_AddClientIDToOpenIDConnectProvider.html) **
  - **Description:** Disables the outbound identity federation feature for the callers account
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_EnableMFADevice.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_EnableMFADevice.html) **
  - **Description:** Grants permission to enable an MFA device and associate it with the specified IAM user
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_RegisterSecurityKey](#awsidentityandaccessmanagementiam-iam_RegisterSecurityKey) <br /> [#awsidentityandaccessmanagementiam-iam_FIDO-FIPS-140-2-certification](#awsidentityandaccessmanagementiam-iam_FIDO-FIPS-140-2-certification) <br /> [#awsidentityandaccessmanagementiam-iam_FIDO-FIPS-140-3-certification](#awsidentityandaccessmanagementiam-iam_FIDO-FIPS-140-3-certification) <br /> [#awsidentityandaccessmanagementiam-iam_FIDO-certification](#awsidentityandaccessmanagementiam-iam_FIDO-certification)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_EnableOrganizationsRootCredentialsManagement.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_EnableOrganizationsRootCredentialsManagement.html) **
  - **Description:** Grants permission to enable the management of member account root user credentials for an organization managed under the current account
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_EnableOrganizationsRootSessions.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_EnableOrganizationsRootSessions.html) **
  - **Description:** Grants permission to enable privileged root actions in member accounts for an organization managed under the current account
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_EnableOutboundWebIdentityFederation.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_EnableOutboundWebIdentityFederation.html) **
  - **Description:** Enables the outbound identity federation feature for the callers account
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GenerateCredentialReport.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GenerateCredentialReport.html) **
  - **Description:** Grants permission to generate a credential report for the AWS account
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GenerateOrganizationsAccessReport.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GenerateOrganizationsAccessReport.html) **
  - **Description:** Grants permission to generate an access report for an AWS Organizations entity
  - **Access level:** Read
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-access-report](#awsidentityandaccessmanagementiam-access-report)  / **Condition keys:**  / **Dependent actions:**  organizations:DescribePolicy <br /> organizations:ListChildren <br /> organizations:ListParents <br /> organizations:ListPoliciesForTarget <br /> organizations:ListRoots <br /> organizations:ListTargetsForPolicy 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_OrganizationsPolicyId](#awsidentityandaccessmanagementiam-iam_OrganizationsPolicyId)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GenerateServiceLastAccessedDetails.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GenerateServiceLastAccessedDetails.html) **
  - **Description:** Grants permission to generate a service last accessed data report for an IAM resource
  - **Access level:** Read
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-group](#awsidentityandaccessmanagementiam-group)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-policy](#awsidentityandaccessmanagementiam-policy)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user)  / **Condition keys:**  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetAccessKeyLastUsed.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetAccessKeyLastUsed.html) **
  - **Description:** Grants permission to retrieve information about when the specified access key was last used
  - **Access level:** Read
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetAccountAuthorizationDetails.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetAccountAuthorizationDetails.html) **
  - **Description:** Grants permission to retrieve information about all IAM users, groups, roles, and policies in your AWS account, including their relationships to one another
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/accounts/latest/reference/manage-acct-update-root-user.html](https://docs.aws.amazon.com/accounts/latest/reference/manage-acct-update-root-user.html) **
  - **Description:** Grants permission to retrieve the email address that is associated with the account
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/accounts/latest/reference/manage-acct-update-root-user.html](https://docs.aws.amazon.com/accounts/latest/reference/manage-acct-update-root-user.html) **
  - **Description:** Grants permission to retrieve the account name that is associated with the account
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetAccountPasswordPolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetAccountPasswordPolicy.html) **
  - **Description:** Grants permission to retrieve the password policy for the AWS account
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetAccountSummary.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetAccountSummary.html) **
  - **Description:** Grants permission to retrieve information about IAM entity usage and IAM quotas in the AWS account
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/private-content-trusted-signers.html](https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/private-content-trusted-signers.html) **
  - **Description:** Grants permission to retrieve information about the specified CloudFront public key
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetContextKeysForCustomPolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetContextKeysForCustomPolicy.html) **
  - **Description:** Grants permission to retrieve a list of all of the context keys that are referenced in the specified policy
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetContextKeysForPrincipalPolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetContextKeysForPrincipalPolicy.html) **
  - **Description:** Grants permission to retrieve a list of all context keys that are referenced in all IAM policies that are attached to the specified IAM identity (user, group, or role)
  - **Access level:** Read
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-group](#awsidentityandaccessmanagementiam-group)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user)  / **Condition keys:**  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetCredentialReport.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetCredentialReport.html) **
  - **Description:** Grants permission to retrieve a credential report for the AWS account
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetDelegationRequest.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetDelegationRequest.html) **
  - **Description:** Retrieves information about a specific delegation request
  - **Access level:** Read
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-delegation-request](#awsidentityandaccessmanagementiam-delegation-request) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetGroup.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetGroup.html) **
  - **Description:** Grants permission to retrieve a list of IAM users in the specified IAM group
  - **Access level:** Read
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-group](#awsidentityandaccessmanagementiam-group) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetGroupPolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetGroupPolicy.html) **
  - **Description:** Grants permission to retrieve an inline policy document that is embedded in the specified IAM group
  - **Access level:** Read
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-group](#awsidentityandaccessmanagementiam-group) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetHumanReadableSummary.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetHumanReadableSummary.html) **
  - **Description:** Retrieves a human readable summary for a given entity. At this time, only delegation request are supported
  - **Access level:** Read
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-delegation-request](#awsidentityandaccessmanagementiam-delegation-request) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetInstanceProfile.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetInstanceProfile.html) **
  - **Description:** Grants permission to retrieve information about the specified instance profile, including the instance profile's path, GUID, ARN, and role
  - **Access level:** Read
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-instance-profile](#awsidentityandaccessmanagementiam-instance-profile) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetLoginProfile.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetLoginProfile.html) **
  - **Description:** Grants permission to retrieve the user name and password creation date for the specified IAM user
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetMFADevice.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetMFADevice.html) **
  - **Description:** Grants permission to retrieve information about an MFA device for the specified user
  - **Access level:** Read
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetOpenIDConnectProvider.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetOpenIDConnectProvider.html) **
  - **Description:** Grants permission to retrieve information about the specified OpenID Connect (OIDC) provider resource in IAM
  - **Access level:** Read
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-oidc-provider](#awsidentityandaccessmanagementiam-oidc-provider) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetOrganizationsAccessReport.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetOrganizationsAccessReport.html) **
  - **Description:** Grants permission to retrieve an AWS Organizations access report
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetOutboundWebIdentityFederationInfo.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetOutboundWebIdentityFederationInfo.html) **
  - **Description:** Retrieves the configuration information for the outbound identity federation feature for the callers account
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetPolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetPolicy.html) **
  - **Description:** Grants permission to retrieve information about the specified managed policy, including the policy's default version and the total number of identities to which the policy is attached
  - **Access level:** Read
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-policy](#awsidentityandaccessmanagementiam-policy) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetPolicyVersion.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetPolicyVersion.html) **
  - **Description:** Grants permission to retrieve information about a version of the specified managed policy, including the policy document
  - **Access level:** Read
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-policy](#awsidentityandaccessmanagementiam-policy) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetRole.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetRole.html) **
  - **Description:** Grants permission to retrieve information about the specified role, including the role's path, GUID, ARN, and the role's trust policy
  - **Access level:** Read
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_PermissionsBoundary](#awsidentityandaccessmanagementiam-iam_PermissionsBoundary)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetRolePolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetRolePolicy.html) **
  - **Description:** Grants permission to retrieve an inline policy document that is embedded with the specified IAM role
  - **Access level:** Read
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetSAMLProvider.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetSAMLProvider.html) **
  - **Description:** Grants permission to retrieve the SAML provider metadocument that was uploaded when the IAM SAML provider resource was created or updated
  - **Access level:** Read
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-saml-provider](#awsidentityandaccessmanagementiam-saml-provider) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetSSHPublicKey.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetSSHPublicKey.html) **
  - **Description:** Grants permission to retrieve the specified SSH public key, including metadata about the key
  - **Access level:** Read
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetServerCertificate.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetServerCertificate.html) **
  - **Description:** Grants permission to retrieve information about the specified server certificate stored in IAM
  - **Access level:** Read
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-server-certificate](#awsidentityandaccessmanagementiam-server-certificate) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetServiceLastAccessedDetails.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetServiceLastAccessedDetails.html) **
  - **Description:** Grants permission to retrieve information about the service last accessed data report
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetServiceLastAccessedDetailsWithEntities.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetServiceLastAccessedDetailsWithEntities.html) **
  - **Description:** Grants permission to retrieve information about the entities from the service last accessed data report
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetServiceLinkedRoleDeletionStatus.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetServiceLinkedRoleDeletionStatus.html) **
  - **Description:** Grants permission to retrieve an IAM service-linked role deletion status
  - **Access level:** Read
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetUser.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetUser.html) **
  - **Description:** Grants permission to retrieve information about the specified IAM user, including the user's creation date, path, unique ID, and ARN
  - **Access level:** Read
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetUserPolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetUserPolicy.html) **
  - **Description:** Grants permission to retrieve an inline policy document that is embedded in the specified IAM user
  - **Access level:** Read
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListAccessKeys.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListAccessKeys.html) **
  - **Description:** Grants permission to list information about the access key IDs that are associated with the specified IAM user
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListAccountAliases.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListAccountAliases.html) **
  - **Description:** Grants permission to list the account alias that is associated with the AWS account
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListAttachedGroupPolicies.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListAttachedGroupPolicies.html) **
  - **Description:** Grants permission to list all managed policies that are attached to the specified IAM group
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-group](#awsidentityandaccessmanagementiam-group) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListAttachedRolePolicies.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListAttachedRolePolicies.html) **
  - **Description:** Grants permission to list all managed policies that are attached to the specified IAM role
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListAttachedUserPolicies.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListAttachedUserPolicies.html) **
  - **Description:** Grants permission to list all managed policies that are attached to the specified IAM user
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/private-content-trusted-signers.html](https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/private-content-trusted-signers.html) **
  - **Description:** Grants permission to list all current CloudFront public keys for the account
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListDelegationRequests.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListDelegationRequests.html) **
  - **Description:** Lists delegation requests based on the specified criteria
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_DelegationRequestOwner](#awsidentityandaccessmanagementiam-iam_DelegationRequestOwner) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListEntitiesForPolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListEntitiesForPolicy.html) **
  - **Description:** Grants permission to list all IAM identities to which the specified managed policy is attached
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-policy](#awsidentityandaccessmanagementiam-policy) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListGroupPolicies.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListGroupPolicies.html) **
  - **Description:** Grants permission to list the names of the inline policies that are embedded in the specified IAM group
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-group](#awsidentityandaccessmanagementiam-group) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListGroups.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListGroups.html) **
  - **Description:** Grants permission to list the IAM groups that have the specified path prefix
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListGroupsForUser.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListGroupsForUser.html) **
  - **Description:** Grants permission to list the IAM groups that the specified IAM user belongs to
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListInstanceProfileTags.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListInstanceProfileTags.html) **
  - **Description:** Grants permission to list the tags that are attached to the specified instance profile
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-instance-profile](#awsidentityandaccessmanagementiam-instance-profile) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListInstanceProfiles.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListInstanceProfiles.html) **
  - **Description:** Grants permission to list the instance profiles that have the specified path prefix
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListInstanceProfilesForRole.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListInstanceProfilesForRole.html) **
  - **Description:** Grants permission to list the instance profiles that have the specified associated IAM role
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListMFADeviceTags.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListMFADeviceTags.html) **
  - **Description:** Grants permission to list the tags that are attached to the specified virtual mfa device
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-mfa](#awsidentityandaccessmanagementiam-mfa) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListMFADevices.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListMFADevices.html) **
  - **Description:** Grants permission to list the MFA devices for an IAM user
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListOpenIDConnectProviderTags.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListOpenIDConnectProviderTags.html) **
  - **Description:** Grants permission to list the tags that are attached to the specified OpenID Connect provider
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-oidc-provider](#awsidentityandaccessmanagementiam-oidc-provider) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListOpenIDConnectProviders.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListOpenIDConnectProviders.html) **
  - **Description:** Grants permission to list information about the IAM OpenID Connect (OIDC) provider resource objects that are defined in the AWS account
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListOrganizationsFeatures.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListOrganizationsFeatures.html) **
  - **Description:** Grants permission to list the centralized root access features enabled for your organization
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListPolicies.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListPolicies.html) **
  - **Description:** Grants permission to list all managed policies
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListPoliciesGrantingServiceAccess.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListPoliciesGrantingServiceAccess.html) **
  - **Description:** Grants permission to list information about the policies that grant an entity access to a specific service
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-group](#awsidentityandaccessmanagementiam-group)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user)  / **Condition keys:**  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListPolicyTags.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListPolicyTags.html) **
  - **Description:** Grants permission to list the tags that are attached to the specified managed policy
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-policy](#awsidentityandaccessmanagementiam-policy) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListPolicyVersions.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListPolicyVersions.html) **
  - **Description:** Grants permission to list information about the versions of the specified managed policy, including the version that is currently set as the policy's default version
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-policy](#awsidentityandaccessmanagementiam-policy) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListRolePolicies.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListRolePolicies.html) **
  - **Description:** Grants permission to list the names of the inline policies that are embedded in the specified IAM role
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListRoleTags.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListRoleTags.html) **
  - **Description:** Grants permission to list the tags that are attached to the specified IAM role
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListRoles.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListRoles.html) **
  - **Description:** Grants permission to list the IAM roles that have the specified path prefix
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListSAMLProviderTags.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListSAMLProviderTags.html) **
  - **Description:** Grants permission to list the tags that are attached to the specified SAML provider
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-saml-provider](#awsidentityandaccessmanagementiam-saml-provider) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListSAMLProviders.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListSAMLProviders.html) **
  - **Description:** Grants permission to list the SAML provider resources in IAM
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListSSHPublicKeys.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListSSHPublicKeys.html) **
  - **Description:** Grants permission to list information about the SSH public keys that are associated with the specified IAM user
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_enable-regions.html](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_enable-regions.html) **
  - **Description:** Grants permission to list the status of all active STS regional endpoints
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListServerCertificateTags.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListServerCertificateTags.html) **
  - **Description:** Grants permission to list the tags that are attached to the specified server certificate
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-server-certificate](#awsidentityandaccessmanagementiam-server-certificate) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListServerCertificates.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListServerCertificates.html) **
  - **Description:** Grants permission to list the server certificates that have the specified path prefix
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListServiceSpecificCredentials.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListServiceSpecificCredentials.html) **
  - **Description:** Grants permission to list the service-specific credentials that are associated with the specified IAM user
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListSigningCertificates.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListSigningCertificates.html) **
  - **Description:** Grants permission to list information about the signing certificates that are associated with the specified IAM user
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListUserPolicies.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListUserPolicies.html) **
  - **Description:** Grants permission to list the names of the inline policies that are embedded in the specified IAM user
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListUserTags.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListUserTags.html) **
  - **Description:** Grants permission to list the tags that are attached to the specified IAM user
  - **Access level:** List
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListUsers.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListUsers.html) **
  - **Description:** Grants permission to list the IAM users that have the specified path prefix
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListVirtualMFADevices.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListVirtualMFADevices.html) **
  - **Description:** Grants permission to list virtual MFA devices by assignment status
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_use_passrole.html](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_use_passrole.html) [permission only]**
  - **Description:** Grants permission to pass a role to a service
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_AssociatedResourceArn](#awsidentityandaccessmanagementiam-iam_AssociatedResourceArn) <br /> [#awsidentityandaccessmanagementiam-iam_PassedToService](#awsidentityandaccessmanagementiam-iam_PassedToService)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_PutGroupPolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_PutGroupPolicy.html) **
  - **Description:** Grants permission to create or update an inline policy document that is embedded in the specified IAM group
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-group](#awsidentityandaccessmanagementiam-group) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_PutRolePermissionsBoundary.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_PutRolePermissionsBoundary.html) **
  - **Description:** Grants permission to set a managed policy as a permissions boundary for a role
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_PermissionsBoundary](#awsidentityandaccessmanagementiam-iam_PermissionsBoundary)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_PutRolePolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_PutRolePolicy.html) **
  - **Description:** Grants permission to create or update an inline policy document that is embedded in the specified IAM role
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_PermissionsBoundary](#awsidentityandaccessmanagementiam-iam_PermissionsBoundary)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_PutUserPermissionsBoundary.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_PutUserPermissionsBoundary.html) **
  - **Description:** Grants permission to set a managed policy as a permissions boundary for an IAM user
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_PermissionsBoundary](#awsidentityandaccessmanagementiam-iam_PermissionsBoundary)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_PutUserPolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_PutUserPolicy.html) **
  - **Description:** Grants permission to create or update an inline policy document that is embedded in the specified IAM user
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_PermissionsBoundary](#awsidentityandaccessmanagementiam-iam_PermissionsBoundary)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_RejectDelegationRequest.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_RejectDelegationRequest.html) **
  - **Description:** Rejects a delegation request, denying the requested temporary access
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-delegation-request](#awsidentityandaccessmanagementiam-delegation-request) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_RemoveClientIDFromOpenIDConnectProvider.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_RemoveClientIDFromOpenIDConnectProvider.html) **
  - **Description:** Grants permission to remove the client ID (audience) from the list of client IDs in the specified IAM OpenID Connect (OIDC) provider resource
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-oidc-provider](#awsidentityandaccessmanagementiam-oidc-provider) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_RemoveRoleFromInstanceProfile.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_RemoveRoleFromInstanceProfile.html) **
  - **Description:** Grants permission to remove an IAM role from the specified EC2 instance profile
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-instance-profile](#awsidentityandaccessmanagementiam-instance-profile) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_RemoveUserFromGroup.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_RemoveUserFromGroup.html) **
  - **Description:** Grants permission to remove an IAM user from the specified group
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-group](#awsidentityandaccessmanagementiam-group) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ResetServiceSpecificCredential.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ResetServiceSpecificCredential.html) **
  - **Description:** Grants permission to reset the password for an existing service-specific credential for an IAM user
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_ServiceSpecificCredentialServiceName](#awsidentityandaccessmanagementiam-iam_ServiceSpecificCredentialServiceName)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_ResyncMFADevice.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_ResyncMFADevice.html) **
  - **Description:** Grants permission to synchronize the specified MFA device with its IAM entity (user or role)
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_SendDelegationToken.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_SendDelegationToken.html) **
  - **Description:** Sends the exchange token for an accepted delegation request
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-delegation-request](#awsidentityandaccessmanagementiam-delegation-request) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_SetDefaultPolicyVersion.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_SetDefaultPolicyVersion.html) **
  - **Description:** Grants permission to set the version of the specified policy as the policy's default version
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-policy](#awsidentityandaccessmanagementiam-policy) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_enable-regions.html](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_enable-regions.html) **
  - **Description:** Grants permission to activate or deactivate an STS regional endpoint
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_SetSecurityTokenServicePreferences.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_SetSecurityTokenServicePreferences.html) **
  - **Description:** Grants permission to set the STS global endpoint token version
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_SimulateCustomPolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_SimulateCustomPolicy.html) **
  - **Description:** Grants permission to simulate whether an identity-based policy or resource-based policy provides permissions for specific API operations and resources
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_SimulatePrincipalPolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_SimulatePrincipalPolicy.html) **
  - **Description:** Grants permission to simulate whether an identity-based policy that is attached to a specified IAM entity (user or role) provides permissions for specific API operations and resources
  - **Access level:** Read
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-group](#awsidentityandaccessmanagementiam-group)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user)  / **Condition keys:**  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_TagInstanceProfile.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_TagInstanceProfile.html) **
  - **Description:** Grants permission to add tags to an instance profile
  - **Access level:** Tagging
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-instance-profile](#awsidentityandaccessmanagementiam-instance-profile)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys) <br /> [#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_](#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_TagMFADevice.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_TagMFADevice.html) **
  - **Description:** Grants permission to add tags to a virtual mfa device
  - **Access level:** Tagging
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-mfa](#awsidentityandaccessmanagementiam-mfa)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys) <br /> [#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_](#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_TagOpenIDConnectProvider.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_TagOpenIDConnectProvider.html) **
  - **Description:** Grants permission to add tags to an OpenID Connect provider
  - **Access level:** Tagging
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-oidc-provider](#awsidentityandaccessmanagementiam-oidc-provider)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys) <br /> [#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_](#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_TagPolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_TagPolicy.html) **
  - **Description:** Grants permission to add tags to a managed policy
  - **Access level:** Tagging
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-policy](#awsidentityandaccessmanagementiam-policy)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys) <br /> [#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_](#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_TagRole.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_TagRole.html) **
  - **Description:** Grants permission to add tags to an IAM role
  - **Access level:** Tagging
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys) <br /> [#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_](#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_TagSAMLProvider.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_TagSAMLProvider.html) **
  - **Description:** Grants permission to add tags to a SAML Provider
  - **Access level:** Tagging
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-saml-provider](#awsidentityandaccessmanagementiam-saml-provider)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys) <br /> [#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_](#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_TagServerCertificate.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_TagServerCertificate.html) **
  - **Description:** Grants permission to add tags to a server certificate
  - **Access level:** Tagging
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-server-certificate](#awsidentityandaccessmanagementiam-server-certificate)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys) <br /> [#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_](#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_TagUser.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_TagUser.html) **
  - **Description:** Grants permission to add tags to an IAM user
  - **Access level:** Tagging
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys) <br /> [#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_](#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UntagInstanceProfile.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UntagInstanceProfile.html) **
  - **Description:** Grants permission to remove the specified tags from the instance profile
  - **Access level:** Tagging
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-instance-profile](#awsidentityandaccessmanagementiam-instance-profile)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UntagMFADevice.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UntagMFADevice.html) **
  - **Description:** Grants permission to remove the specified tags from the virtual mfa device
  - **Access level:** Tagging
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-mfa](#awsidentityandaccessmanagementiam-mfa)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UntagOpenIDConnectProvider.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UntagOpenIDConnectProvider.html) **
  - **Description:** Grants permission to remove the specified tags from the OpenID Connect provider
  - **Access level:** Tagging
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-oidc-provider](#awsidentityandaccessmanagementiam-oidc-provider)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UntagPolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UntagPolicy.html) **
  - **Description:** Grants permission to remove the specified tags from the managed policy
  - **Access level:** Tagging
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-policy](#awsidentityandaccessmanagementiam-policy)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UntagRole.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UntagRole.html) **
  - **Description:** Grants permission to remove the specified tags from the role
  - **Access level:** Tagging
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UntagSAMLProvider.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UntagSAMLProvider.html) **
  - **Description:** Grants permission to remove the specified tags from the SAML Provider
  - **Access level:** Tagging
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-saml-provider](#awsidentityandaccessmanagementiam-saml-provider)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UntagServerCertificate.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UntagServerCertificate.html) **
  - **Description:** Grants permission to remove the specified tags from the server certificate
  - **Access level:** Tagging
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-server-certificate](#awsidentityandaccessmanagementiam-server-certificate)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UntagUser.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UntagUser.html) **
  - **Description:** Grants permission to remove the specified tags from the user
  - **Access level:** Tagging
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateAccessKey.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateAccessKey.html) **
  - **Description:** Grants permission to update the status of the specified access key as Active or Inactive
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/accounts/latest/reference/manage-acct-update-root-user.html](https://docs.aws.amazon.com/accounts/latest/reference/manage-acct-update-root-user.html) **
  - **Description:** Grants permission to update the email address that is associated with the account
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/accounts/latest/reference/manage-acct-update-root-user.html](https://docs.aws.amazon.com/accounts/latest/reference/manage-acct-update-root-user.html) **
  - **Description:** Grants permission to update the account name that is associated with the account
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateAccountPasswordPolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateAccountPasswordPolicy.html) **
  - **Description:** Grants permission to update the password policy settings for the AWS account
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateAssumeRolePolicy.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateAssumeRolePolicy.html) **
  - **Description:** Grants permission to update the policy that grants an IAM entity permission to assume a role
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_PermissionsBoundary](#awsidentityandaccessmanagementiam-iam_PermissionsBoundary)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/private-content-trusted-signers.html](https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/private-content-trusted-signers.html) **
  - **Description:** Grants permission to update an existing CloudFront public key
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateGroup.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateGroup.html) **
  - **Description:** Grants permission to update the name or path of the specified IAM group
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-group](#awsidentityandaccessmanagementiam-group) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateLoginProfile.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateLoginProfile.html) **
  - **Description:** Grants permission to change the password for the specified IAM user
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateOpenIDConnectProviderThumbprint.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateOpenIDConnectProviderThumbprint.html) **
  - **Description:** Grants permission to update the entire list of server certificate thumbprints that are associated with an OpenID Connect (OIDC) provider resource
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-oidc-provider](#awsidentityandaccessmanagementiam-oidc-provider) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateRole.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateRole.html) **
  - **Description:** Grants permission to update the description or maximum session duration setting of a role
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_PermissionsBoundary](#awsidentityandaccessmanagementiam-iam_PermissionsBoundary)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateRoleDescription.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateRoleDescription.html) **
  - **Description:** Grants permission to update only the description of a role
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-role](#awsidentityandaccessmanagementiam-role)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_PermissionsBoundary](#awsidentityandaccessmanagementiam-iam_PermissionsBoundary)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateSAMLProvider.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateSAMLProvider.html) **
  - **Description:** Grants permission to update the metadata document for an existing SAML provider resource
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-saml-provider](#awsidentityandaccessmanagementiam-saml-provider) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateSSHPublicKey.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateSSHPublicKey.html) **
  - **Description:** Grants permission to update the status of an IAM user's SSH public key to active or inactive
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateServerCertificate.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateServerCertificate.html) **
  - **Description:** Grants permission to update the name or the path of the specified server certificate stored in IAM
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-server-certificate](#awsidentityandaccessmanagementiam-server-certificate) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateServiceSpecificCredential.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateServiceSpecificCredential.html) **
  - **Description:** Grants permission to update the status of a service-specific credential to active or inactive for an IAM user
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-iam_ServiceSpecificCredentialServiceName](#awsidentityandaccessmanagementiam-iam_ServiceSpecificCredentialServiceName)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateSigningCertificate.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateSigningCertificate.html) **
  - **Description:** Grants permission to update the status of the specified user signing certificate to active or disabled
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateUser.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateUser.html) **
  - **Description:** Grants permission to update the name or the path of the specified IAM user
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/private-content-trusted-signers.html](https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/private-content-trusted-signers.html) **
  - **Description:** Grants permission to upload a CloudFront public key
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UploadSSHPublicKey.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UploadSSHPublicKey.html) **
  - **Description:** Grants permission to upload an SSH public key and associate it with the specified IAM user
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UploadServerCertificate.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UploadServerCertificate.html) **
  - **Description:** Grants permission to upload a server certificate entity for the AWS account
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-server-certificate](#awsidentityandaccessmanagementiam-server-certificate)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#awsidentityandaccessmanagementiam-aws_TagKeys](#awsidentityandaccessmanagementiam-aws_TagKeys) <br /> [#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_](#awsidentityandaccessmanagementiam-aws_RequestTag___TagKey_)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/IAM/latest/APIReference/API_UploadSigningCertificate.html](https://docs.aws.amazon.com/IAM/latest/APIReference/API_UploadSigningCertificate.html) **
  - **Description:** Grants permission to upload an X.509 signing certificate and associate it with the specified IAM user
  - **Access level:** Write
  - **Resource types (\*required):**  [#awsidentityandaccessmanagementiam-user](#awsidentityandaccessmanagementiam-user) 
  - **Condition keys:** 
  - **Dependent actions:** 



## Resource types defined by AWS Identity and Access Management (IAM)
<a name="awsidentityandaccessmanagementiam-resources-for-iam-policies"></a>

The following resource types are defined by this service and can be used in the `Resource` element of IAM permission policy statements. Each action in the [Actions table](#awsidentityandaccessmanagementiam-actions-as-permissions) identifies the resource types that can be specified with that action. A resource type can also define which condition keys you can include in a policy. These keys are displayed in the last column of the table. For details about the columns in the following table, see [Resource types table](reference_policies_actions-resources-contextkeys.html#resources_table).


****  

| Resource types | ARN | Condition keys | 
| --- | --- | --- | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_access-advisor-view-data-orgs.html](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_access-advisor-view-data-orgs.html)  |  arn:${Partition}:iam::${Account}:access-report/${EntityPath}  |  | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html)  |  arn:${Partition}:iam::${Account}:assumed-role/${RoleName}/${RoleSessionName}  |  | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_saml.html](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_saml.html)  |  arn:${Partition}:iam::${Account}:federated-user/${UserName}  |  | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/id_groups.html](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_groups.html)  |  arn:${Partition}:iam::${Account}:group/${GroupNameWithPath}  |  | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_use_switch-role-ec2_instance-profiles.html](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_use_switch-role-ec2_instance-profiles.html)  |  arn:${Partition}:iam::${Account}:instance-profile/${InstanceProfileNameWithPath}  |  [#awsidentityandaccessmanagementiam-aws_ResourceTag___TagKey_](#awsidentityandaccessmanagementiam-aws_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa.html](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa.html)  |  arn:${Partition}:iam::${Account}:mfa/${MfaTokenIdWithPath}  |  [#awsidentityandaccessmanagementiam-aws_ResourceTag___TagKey_](#awsidentityandaccessmanagementiam-aws_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_create_oidc.html](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_create_oidc.html)  |  arn:${Partition}:iam::${Account}:oidc-provider/${OidcProviderName}  |  [#awsidentityandaccessmanagementiam-aws_ResourceTag___TagKey_](#awsidentityandaccessmanagementiam-aws_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_managed-vs-inline.html](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_managed-vs-inline.html)  |  arn:${Partition}:iam::${Account}:policy/${PolicyNameWithPath}  |  [#awsidentityandaccessmanagementiam-aws_ResourceTag___TagKey_](#awsidentityandaccessmanagementiam-aws_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles.html](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles.html)  |  arn:${Partition}:iam::${Account}:role/${RoleNameWithPath}  |  [#awsidentityandaccessmanagementiam-aws_ResourceTag___TagKey_](#awsidentityandaccessmanagementiam-aws_ResourceTag___TagKey_) <br /> [#awsidentityandaccessmanagementiam-iam_ResourceTag___TagKey_](#awsidentityandaccessmanagementiam-iam_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_saml.html](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_saml.html)  |  arn:${Partition}:iam::${Account}:saml-provider/${SamlProviderName}  |  [#awsidentityandaccessmanagementiam-aws_ResourceTag___TagKey_](#awsidentityandaccessmanagementiam-aws_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_server-certs.html](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_server-certs.html)  |  arn:${Partition}:iam::${Account}:server-certificate/${CertificateNameWithPath}  |  [#awsidentityandaccessmanagementiam-aws_ResourceTag___TagKey_](#awsidentityandaccessmanagementiam-aws_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa.html](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa.html)  |  arn:${Partition}:iam::${Account}:sms-mfa/${MfaTokenIdWithPath}  |  | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users.html](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users.html)  |  arn:${Partition}:iam::${Account}:user/${UserNameWithPath}  |  [#awsidentityandaccessmanagementiam-aws_ResourceTag___TagKey_](#awsidentityandaccessmanagementiam-aws_ResourceTag___TagKey_) <br /> [#awsidentityandaccessmanagementiam-iam_ResourceTag___TagKey_](#awsidentityandaccessmanagementiam-iam_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies-temporary-delegation.html](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies-temporary-delegation.html)  |  arn:${Partition}:iam::${Account}:delegation-request/${DelegationRequestId}  |  [#awsidentityandaccessmanagementiam-iam_DelegationRequestOwner](#awsidentityandaccessmanagementiam-iam_DelegationRequestOwner)  | 

## Condition keys for AWS Identity and Access Management (IAM)
<a name="awsidentityandaccessmanagementiam-policy-keys"></a>

AWS Identity and Access Management (IAM) defines the following condition keys that can be used in the `Condition` element of an IAM policy. You can use these keys to further refine the conditions under which the policy statement applies. For details about the columns in the following table, see [Condition keys table](reference_policies_actions-resources-contextkeys.html#context_keys_table).

To view the global condition keys that are available to all services, see [AWS global condition context keys](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html).


****  

| Condition keys | Description | Type | 
| --- | --- | --- | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-requesttag](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-requesttag)  | Filters access based on the tags that are passed in the request | String | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-resourcetag](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-resourcetag)  | Filters access based on the tags associated with the resource | String | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-tagkeys](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-tagkeys)  | Filters access based on the tag keys that are passed in the request | ArrayOfString | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_AWSServiceName](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_AWSServiceName)  | Filters access by the AWS service to which this role is attached | String | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_AssociatedResourceArn](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_AssociatedResourceArn)  | Filters access by the resource that the role will be used on behalf of | ARN | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_DelegationDuration](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_DelegationDuration)  | Filters access based on the requested delegation duration | String | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_DelegationRequestOwner](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_DelegationRequestOwner)  | Filters access based on the delegation request owner | ARN | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_FIDO-FIPS-140-2-certification](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_FIDO-FIPS-140-2-certification)  | Filters access by the MFA device FIPS-140-2 validation certification level at the time of registration of a FIDO security key | String | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_FIDO-FIPS-140-3-certification](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_FIDO-FIPS-140-3-certification)  | Filters access by the MFA device FIPS-140-3 validation certification level at the time of registration of a FIDO security key | String | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_FIDO-certification](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_FIDO-certification)  | Filters access by the MFA device FIDO certification level at the time of registration of a FIDO security key | String | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_NotificationChannel](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_NotificationChannel)  | Filters access based on the requested notification channel | String | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_OrganizationsPolicyId](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_OrganizationsPolicyId)  | Filters access by the ID of an AWS Organizations policy | String | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_PassedToService](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_PassedToService)  | Filters access by the AWS service to which this role is passed | String | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_PermissionsBoundary](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_PermissionsBoundary)  | Filters access if the specified policy is set as the permissions boundary on the IAM entity (user or role) | ARN | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_PolicyARN](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_PolicyARN)  | Filters access by the ARN of an IAM policy | ARN | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_RegisterSecurityKey](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_RegisterSecurityKey)  | Filters access by the current state of MFA device enablement | String | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_ResourceTag](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_ResourceTag)  | Filters access by the tags attached to an IAM entity (user or role) | String | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_ServiceSpecificCredentialAgeDays](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_ServiceSpecificCredentialAgeDays)  | Filters access by the duration until the credential's expiration | Numeric | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_ServiceSpecificCredentialServiceName](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_ServiceSpecificCredentialServiceName)  | Filters access by the service associated with the credential | String | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_TemplateArn](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_TemplateArn)  | Filters access based on the requested template ARN | ARN | 