View a markdown version of this page

Actions, resources, and condition keys for AWS Identity and Access Management (IAM) - Service Authorization Reference

Actions, resources, and condition keys for AWS Identity and Access Management (IAM)

AWS Identity and Access Management (IAM) (service prefix: iam) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS Identity and Access Management (IAM)

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation SDK client IAM action Condition key Possible value(s) Access level

AcceptDelegationRequest

iam

iam:AcceptDelegationRequest

Write

AcquireRole

iam

iam:AttachRolePolicy

Permissions management, Write

iam:CreateRole

Write

iam:GetRole

Read

iam:GetRoleTemplateVersion

Read

iam:PutRolePermissionsBoundary

Permissions management, Write

iam:PutRolePolicy

Permissions management, Write

iam:TagRole

Tagging, Write

AddClientIDToOpenIDConnectProvider

iam

iam:AddClientIDToOpenIDConnectProvider

Write

AddRoleToInstanceProfile

iam

iam:AddRoleToInstanceProfile

Write

iam:PassRole

iam:PassedToService

ec2.amazonaws.com

Write

AddUserToGroup

iam

iam:AddUserToGroup

Write

AssociateDelegationRequest

iam

iam:AssociateDelegationRequest

Write

AttachGroupPolicy

iam

iam:AttachGroupPolicy

Permissions management, Write

AttachRolePolicy

iam

iam:AttachRolePolicy

Permissions management, Write

AttachUserPolicy

iam

iam:AttachUserPolicy

Permissions management, Write

ChangePassword

iam

iam:ChangePassword

Write

CreateAccessKey

iam

iam:CreateAccessKey

Write

CreateAccountAlias

iam

iam:CreateAccountAlias

Write

CreateDelegationRequest

iam

iam:CreateDelegationRequest

Write

CreateGroup

iam

iam:CreateGroup

Write

CreateInstanceProfile

iam

iam:CreateInstanceProfile

Write

iam:TagInstanceProfile

Tagging, Write

CreateLoginProfile

iam

iam:CreateLoginProfile

Write

CreateOpenIDConnectProvider

iam

iam:CreateOpenIDConnectProvider

Write

iam:TagOpenIDConnectProvider

Tagging, Write

CreatePolicy

iam

iam:CreatePolicy

Permissions management, Write

iam:TagPolicy

Tagging, Write

CreatePolicyVersion

iam

iam:CreatePolicyVersion

Permissions management, Write

CreateRole

iam

iam:CreateRole

Write

iam:TagRole

Tagging, Write

CreateSAMLProvider

iam

iam:CreateSAMLProvider

Write

iam:TagSAMLProvider

Tagging, Write

CreateServiceLinkedRole

iam

iam:CreateServiceLinkedRole

Write

iam:PutRolePolicy

Permissions management, Write

CreateServiceSpecificCredential

iam

iam:CreateServiceSpecificCredential

Write

CreateUser

iam

iam:CreateUser

Write

iam:TagUser

Tagging, Write

CreateVirtualMFADevice

iam

iam:CreateVirtualMFADevice

Write

iam:TagMFADevice

Tagging, Write

DeactivateMFADevice

iam

iam:DeactivateMFADevice

Write

DeleteAccessKey

iam

iam:DeleteAccessKey

Write

DeleteAccountAlias

iam

iam:DeleteAccountAlias

Write

DeleteAccountPasswordPolicy

iam

iam:DeleteAccountPasswordPolicy

Permissions management, Write

DeleteGroup

iam

iam:DeleteGroup

Write

DeleteGroupPolicy

iam

iam:DeleteGroupPolicy

Permissions management, Write

DeleteInstanceProfile

iam

iam:DeleteInstanceProfile

Write

DeleteLoginProfile

iam

iam:DeleteLoginProfile

Write

DeleteOpenIDConnectProvider

iam

iam:DeleteOpenIDConnectProvider

Write

DeletePolicy

iam

iam:DeletePolicy

Permissions management, Write

DeletePolicyVersion

iam

iam:DeletePolicyVersion

Permissions management, Write

DeleteRole

iam

iam:DeleteRole

Write

DeleteRolePermissionsBoundary

iam

iam:DeleteRolePermissionsBoundary

Permissions management, Write

DeleteRolePolicy

iam

iam:DeleteRolePolicy

Permissions management, Write

DeleteSAMLProvider

iam

iam:DeleteSAMLProvider

Write

DeleteSSHPublicKey

iam

iam:DeleteSSHPublicKey

Write

DeleteServerCertificate

iam

iam:DeleteServerCertificate

Write

DeleteServiceLinkedRole

iam

iam:DeleteServiceLinkedRole

Write

DeleteServiceSpecificCredential

iam

iam:DeleteServiceSpecificCredential

Write

DeleteSigningCertificate

iam

iam:DeleteSigningCertificate

Write

DeleteUser

iam

iam:DeleteUser

Write

DeleteUserPermissionsBoundary

iam

iam:DeleteUserPermissionsBoundary

Permissions management, Write

DeleteUserPolicy

iam

iam:DeleteUserPolicy

Permissions management, Write

DeleteVirtualMFADevice

iam

iam:DeleteVirtualMFADevice

Write

DetachGroupPolicy

iam

iam:DetachGroupPolicy

Permissions management, Write

DetachRolePolicy

iam

iam:DetachRolePolicy

Permissions management, Write

DetachUserPolicy

iam

iam:DetachUserPolicy

Permissions management, Write

DisableOutboundWebIdentityFederation

iam

iam:DisableOutboundWebIdentityFederation

Write

EnableMFADevice

iam

iam:EnableMFADevice

Write

EnableOutboundWebIdentityFederation

iam

iam:EnableOutboundWebIdentityFederation

Write

GenerateCredentialReport

iam

iam:GenerateCredentialReport

Read

GenerateOrganizationsAccessReport

iam

iam:GenerateOrganizationsAccessReport

Read

GenerateServiceLastAccessedDetails

iam

iam:GenerateServiceLastAccessedDetails

Read

GetAccessKeyLastUsed

iam

iam:GetAccessKeyLastUsed

Read

GetAccountAuthorizationDetails

iam

iam:GetAccountAuthorizationDetails

Read

GetAccountPasswordPolicy

iam

iam:GetAccountPasswordPolicy

Read

GetAccountProperties

iam

iam:GetAccountProperties

Read

GetAccountSummary

iam

iam:GetAccountSummary

List

GetContextKeysForCustomPolicy

iam

iam:GetContextKeysForCustomPolicy

Read

GetContextKeysForPrincipalPolicy

iam

iam:GetContextKeysForPrincipalPolicy

Read

GetCredentialReport

iam

iam:GetCredentialReport

Read

GetDelegationRequest

iam

iam:GetDelegationRequest

Read

GetGroup

iam

iam:GetGroup

Read

GetGroupPolicy

iam

iam:GetGroupPolicy

Read

GetHumanReadableSummary

iam

iam:GetHumanReadableSummary

Read

GetInstanceProfile

iam

iam:GetInstanceProfile

Read

GetLoginProfile

iam

iam:GetLoginProfile

List

GetMFADevice

iam

iam:GetMFADevice

Read

GetOpenIDConnectProvider

iam

iam:GetOpenIDConnectProvider

Read

GetOrganizationsAccessReport

iam

iam:GetOrganizationsAccessReport

Read

GetOutboundWebIdentityFederationInfo

iam

iam:GetOutboundWebIdentityFederationInfo

Read

GetPolicy

iam

iam:GetPolicy

Read

GetPolicyVersion

iam

iam:GetPolicyVersion

Read

GetRole

iam

iam:GetRole

Read

GetRolePolicy

iam

iam:GetRolePolicy

Read

GetRoleTemplateVersion

iam

iam:GetRoleTemplateVersion

Read

GetSAMLProvider

iam

iam:GetSAMLProvider

Read

GetSSHPublicKey

iam

iam:GetSSHPublicKey

Read

GetServerCertificate

iam

iam:GetServerCertificate

Read

GetServiceLastAccessedDetails

iam

iam:GetServiceLastAccessedDetails

Read

GetServiceLastAccessedDetailsWithEntities

iam

iam:GetServiceLastAccessedDetailsWithEntities

Read

GetServiceLinkedRoleDeletionStatus

iam

iam:GetServiceLinkedRoleDeletionStatus

Read

GetUser

iam

iam:GetUser

Read

GetUserPolicy

iam

iam:GetUserPolicy

Read

ListAccessKeys

iam

iam:ListAccessKeys

List

ListAccountAliases

iam

iam:ListAccountAliases

List

ListAttachedGroupPolicies

iam

iam:ListAttachedGroupPolicies

List

ListAttachedRolePolicies

iam

iam:ListAttachedRolePolicies

List

ListAttachedUserPolicies

iam

iam:ListAttachedUserPolicies

List

ListDelegationRequests

iam

iam:ListDelegationRequests

List

ListEntitiesForPolicy

iam

iam:ListEntitiesForPolicy

List

ListGroupPolicies

iam

iam:ListGroupPolicies

List

ListGroups

iam

iam:ListGroups

List

ListGroupsForUser

iam

iam:ListGroupsForUser

List

ListInstanceProfileTags

iam

iam:ListInstanceProfileTags

List

ListInstanceProfiles

iam

iam:ListInstanceProfiles

List

ListInstanceProfilesForRole

iam

iam:ListInstanceProfilesForRole

List

ListMFADeviceTags

iam

iam:ListMFADeviceTags

List

ListMFADevices

iam

iam:ListMFADevices

List

ListOpenIDConnectProviderTags

iam

iam:ListOpenIDConnectProviderTags

List

ListOpenIDConnectProviders

iam

iam:ListOpenIDConnectProviders

List

ListPolicies

iam

iam:ListPolicies

List

ListPoliciesGrantingServiceAccess

iam

iam:ListPoliciesGrantingServiceAccess

List

ListPolicyTags

iam

iam:ListPolicyTags

List

ListPolicyVersions

iam

iam:ListPolicyVersions

List

ListRolePolicies

iam

iam:ListRolePolicies

List

ListRoleTags

iam

iam:ListRoleTags

List

ListRoles

iam

iam:ListRoles

List

ListSAMLProviderTags

iam

iam:ListSAMLProviderTags

List

ListSAMLProviders

iam

iam:ListSAMLProviders

List

ListSSHPublicKeys

iam

iam:ListSSHPublicKeys

List

ListServerCertificateTags

iam

iam:ListServerCertificateTags

List

ListServerCertificates

iam

iam:ListServerCertificates

List

ListServiceSpecificCredentials

iam

iam:ListServiceSpecificCredentials

List

ListSigningCertificates

iam

iam:ListSigningCertificates

List

ListUserPolicies

iam

iam:ListUserPolicies

List

ListUserTags

iam

iam:ListUserTags

List

ListUsers

iam

iam:ListUsers

List

ListVirtualMFADevices

iam

iam:ListVirtualMFADevices

List

PutAccountProperties

iam

iam:CreateServiceLinkedRole

Write

iam:PutAccountProperties

Write

PutGroupPolicy

iam

iam:PutGroupPolicy

Permissions management, Write

PutRolePermissionsBoundary

iam

iam:PutRolePermissionsBoundary

Permissions management, Write

PutRolePolicy

iam

iam:PutRolePolicy

Permissions management, Write

PutUserPermissionsBoundary

iam

iam:PutUserPermissionsBoundary

Permissions management, Write

PutUserPolicy

iam

iam:PutUserPolicy

Permissions management, Write

RejectDelegationRequest

iam

iam:RejectDelegationRequest

Write

RemoveClientIDFromOpenIDConnectProvider

iam

iam:RemoveClientIDFromOpenIDConnectProvider

Write

RemoveRoleFromInstanceProfile

iam

iam:RemoveRoleFromInstanceProfile

Write

RemoveUserFromGroup

iam

iam:RemoveUserFromGroup

Write

ResetServiceSpecificCredential

iam

iam:ResetServiceSpecificCredential

Write

ResyncMFADevice

iam

iam:ResyncMFADevice

Write

SendDelegationToken

iam

iam:SendDelegationToken

Write

SetDefaultPolicyVersion

iam

iam:SetDefaultPolicyVersion

Permissions management, Write

SetSecurityTokenServicePreferences

iam

iam:SetSecurityTokenServicePreferences

Write

SimulateCustomPolicy

iam

iam:SimulateCustomPolicy

Read

SimulatePrincipalPolicy

iam

iam:SimulatePrincipalPolicy

Read

TagInstanceProfile

iam

iam:TagInstanceProfile

Tagging, Write

TagMFADevice

iam

iam:TagMFADevice

Tagging, Write

TagOpenIDConnectProvider

iam

iam:TagOpenIDConnectProvider

Tagging, Write

TagPolicy

iam

iam:TagPolicy

Tagging, Write

TagRole

iam

iam:TagRole

Tagging, Write

TagSAMLProvider

iam

iam:TagSAMLProvider

Tagging, Write

TagServerCertificate

iam

iam:TagServerCertificate

Tagging, Write

TagUser

iam

iam:TagUser

Tagging, Write

UntagInstanceProfile

iam

iam:UntagInstanceProfile

Tagging, Write

UntagMFADevice

iam

iam:UntagMFADevice

Tagging, Write

UntagOpenIDConnectProvider

iam

iam:UntagOpenIDConnectProvider

Tagging, Write

UntagPolicy

iam

iam:UntagPolicy

Tagging, Write

UntagRole

iam

iam:UntagRole

Tagging, Write

UntagSAMLProvider

iam

iam:UntagSAMLProvider

Tagging, Write

UntagServerCertificate

iam

iam:UntagServerCertificate

Tagging, Write

UntagUser

iam

iam:UntagUser

Tagging, Write

UpdateAccessKey

iam

iam:UpdateAccessKey

Write

UpdateAccountPasswordPolicy

iam

iam:UpdateAccountPasswordPolicy

Write

UpdateAssumeRolePolicy

iam

iam:UpdateAssumeRolePolicy

Permissions management, Write

UpdateGroup

iam

iam:UpdateGroup

Write

UpdateLoginProfile

iam

iam:UpdateLoginProfile

Write

UpdateOpenIDConnectProviderThumbprint

iam

iam:UpdateOpenIDConnectProviderThumbprint

Write

UpdateRole

iam

iam:UpdateRole

Write

UpdateRoleDescription

iam

iam:UpdateRoleDescription

Write

UpdateSAMLProvider

iam

iam:UpdateSAMLProvider

Write

UpdateSSHPublicKey

iam

iam:UpdateSSHPublicKey

Write

UpdateServerCertificate

iam

iam:UpdateServerCertificate

Write

UpdateServiceSpecificCredential

iam

iam:UpdateServiceSpecificCredential

Write

UpdateSigningCertificate

iam

iam:UpdateSigningCertificate

Write

UpdateUser

iam

iam:UpdateUser

Write

UploadSSHPublicKey

iam

iam:UploadSSHPublicKey

Write

UploadServerCertificate

iam

iam:TagServerCertificate

Tagging, Write

iam:UploadServerCertificate

Write

UploadSigningCertificate

iam

iam:UploadSigningCertificate

Write

Actions defined by AWS Identity and Access Management (IAM)

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

AcceptDelegationRequest

Accepts a delegation request resource, granting the requested temporary access

delegation-request*

iam:DelegationRequestOwner

Write

AddClientIDToOpenIDConnectProvider

Grants permission to add a new client ID (audience) to the list of registered IDs for the specified IAM OpenID Connect (OIDC) provider resource

oidc-provider*

aws:ResourceTag/${TagKey}

Write

AddRoleToInstanceProfile

Grants permission to add an IAM role to the specified instance profile

instance-profile*

aws:ResourceTag/${TagKey}

Write

AddUserToGroup

Grants permission to add an IAM user to the specified IAM group

group*

Write

AssociateDelegationRequest

Associates a delegation request resource with the calling identity

delegation-request*

iam:DelegationRequestOwner

Write

AttachGroupPolicy

Grants permission to attach a managed policy to the specified IAM group

group*

iam:PolicyARN

Permissions management, Write

AttachRolePolicy

Grants permission to attach a managed policy to the specified IAM role

role*

aws:ResourceTag/${TagKey}

iam:PermissionsBoundary

iam:PolicyARN

iam:ResourceTag/${TagKey}

iam:RoleTemplateARN

Permissions management, Write

AttachUserPolicy

Grants permission to attach a managed policy to the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:PermissionsBoundary

iam:PolicyARN

iam:ResourceTag/${TagKey}

Permissions management, Write

ChangePassword

Grants permission to an IAM user to change their own password

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Write

CreateAccessKey

Grants permission to create access key and secret access key for the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Write

CreateAccountAlias

Grants permission to create an alias for your AWS account

Write

CreateDelegationRequest

Creates an IAM delegation request resource for temporary access delegation

delegation-request*

iam:DelegationDuration

iam:DelegationRequestOwner

iam:NotificationChannel

iam:TemplateArn

Write

CreateGroup

Grants permission to create a new group

group*

Write

CreateInstanceProfile

Grants permission to create a new instance profile

instance-profile*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreateLoginProfile

Grants permission to create a password for the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Write

CreateOpenIDConnectProvider

Grants permission to create an IAM resource that describes an identity provider (IdP) that supports OpenID Connect (OIDC)

oidc-provider*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreatePolicy

Grants permission to create a new managed policy

policy*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Permissions management, Write

CreatePolicyVersion

Grants permission to create a new version of the specified managed policy

policy*

aws:ResourceTag/${TagKey}

Permissions management, Write

CreateRole

Grants permission to create a new role

role*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

iam:PermissionsBoundary

iam:ResourceTag/${TagKey}

iam:RoleTemplateARN

Write

CreateSAMLProvider

Grants permission to create an IAM resource that describes an identity provider (IdP) that supports SAML 2.0

saml-provider*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreateServiceLinkedRole

Grants permission to create an IAM role that allows an AWS service to perform actions on your behalf

role*

aws:ResourceTag/${TagKey}

iam:AWSServiceName

iam:ResourceTag/${TagKey}

Write

CreateServiceSpecificCredential

Grants permission to create a new service-specific credential for an IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

iam:ServiceSpecificCredentialAgeDays

iam:ServiceSpecificCredentialServiceName

Write

CreateUser

Grants permission to create a new IAM user

user*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

iam:PermissionsBoundary

iam:ResourceTag/${TagKey}

Write

CreateVirtualMFADevice

Grants permission to create a new virtual MFA device

mfa*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

DeactivateMFADevice

Grants permission to deactivate the specified MFA device and remove its association with the IAM user for which it was originally enabled

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Write

DeleteAccessKey

Grants permission to delete the access key pair that is associated with the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Write

DeleteAccountAlias

Grants permission to delete the specified AWS account alias

Write

DeleteAccountPasswordPolicy

Grants permission to delete the password policy for the AWS account

Permissions management, Write

DeleteCloudFrontPublicKey

Grants permission to delete an existing CloudFront public key

Write

DeleteGroup

Grants permission to delete the specified IAM group

group*

Write

DeleteGroupPolicy

Grants permission to delete the specified inline policy from its group

group*

Permissions management, Write

DeleteInstanceProfile

Grants permission to delete the specified instance profile

instance-profile*

aws:ResourceTag/${TagKey}

Write

DeleteLoginProfile

Grants permission to delete the password for the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Write

DeleteOpenIDConnectProvider

Grants permission to delete an OpenID Connect identity provider (IdP) resource object in IAM

oidc-provider*

aws:ResourceTag/${TagKey}

Write

DeletePolicy

Grants permission to delete the specified managed policy and remove it from any IAM entities (users, groups, or roles) to which it is attached

policy*

aws:ResourceTag/${TagKey}

Permissions management, Write

DeletePolicyVersion

Grants permission to delete a version from the specified managed policy

policy*

aws:ResourceTag/${TagKey}

Permissions management, Write

DeleteRole

Grants permission to delete the specified role

role*

aws:ResourceTag/${TagKey}

iam:PermissionsBoundary

iam:ResourceTag/${TagKey}

Write

DeleteRolePermissionsBoundary

Grants permission to remove the permissions boundary from a role

role*

aws:ResourceTag/${TagKey}

iam:PermissionsBoundary

iam:ResourceTag/${TagKey}

Permissions management, Write

DeleteRolePolicy

Grants permission to delete the specified inline policy from the specified role

role*

aws:ResourceTag/${TagKey}

iam:PermissionsBoundary

iam:ResourceTag/${TagKey}

Permissions management, Write

DeleteSAMLProvider

Grants permission to delete a SAML provider resource in IAM

saml-provider*

aws:ResourceTag/${TagKey}

Write

DeleteSSHPublicKey

Grants permission to delete the specified SSH public key

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Write

DeleteServerCertificate

Grants permission to delete the specified server certificate

server-certificate*

aws:ResourceTag/${TagKey}

Write

DeleteServiceLinkedRole

Grants permission to delete an IAM role that is linked to a specific AWS service, if the service is no longer using it

role*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Write

DeleteServiceSpecificCredential

Grants permission to delete the specified service-specific credential for an IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

iam:ServiceSpecificCredentialServiceName

Write

DeleteSigningCertificate

Grants permission to delete a signing certificate that is associated with the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Write

DeleteUser

Grants permission to delete the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Write

DeleteUserPermissionsBoundary

Grants permission to remove the permissions boundary from the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:PermissionsBoundary

iam:ResourceTag/${TagKey}

Permissions management, Write

DeleteUserPolicy

Grants permission to delete the specified inline policy from an IAM user

user*

aws:ResourceTag/${TagKey}

iam:PermissionsBoundary

iam:ResourceTag/${TagKey}

Permissions management, Write

DeleteVirtualMFADevice

Grants permission to delete a virtual MFA device

mfa

aws:ResourceTag/${TagKey}

Write

sms-mfa

DetachGroupPolicy

Grants permission to detach a managed policy from the specified IAM group

group*

iam:PolicyARN

Permissions management, Write

DetachRolePolicy

Grants permission to detach a managed policy from the specified role

role*

aws:ResourceTag/${TagKey}

iam:PermissionsBoundary

iam:PolicyARN

iam:ResourceTag/${TagKey}

Permissions management, Write

DetachUserPolicy

Grants permission to detach a managed policy from the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:PermissionsBoundary

iam:PolicyARN

iam:ResourceTag/${TagKey}

Permissions management, Write

DisableOrganizationsRootCredentialsManagement

Grants permission to disable the management of member account root user credentials for an organization managed under the current account

Write

DisableOrganizationsRootSessions

Grants permission to disable privileged root actions in member accounts for an organization managed under the current account

Write

DisableOutboundWebIdentityFederation

Disables the outbound identity federation feature for the callers account

Write

EnableMFADevice

Grants permission to enable an MFA device and associate it with the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:FIDO-certification

iam:FIDO-FIPS-140-2-certification

iam:FIDO-FIPS-140-3-certification

iam:RegisterSecurityKey

iam:ResourceTag/${TagKey}

Write

EnableOrganizationsRootCredentialsManagement

Grants permission to enable the management of member account root user credentials for an organization managed under the current account

Write

EnableOrganizationsRootSessions

Grants permission to enable privileged root actions in member accounts for an organization managed under the current account

Write

EnableOutboundWebIdentityFederation

Enables the outbound identity federation feature for the callers account

Write

GenerateCredentialReport

Grants permission to generate a credential report for the AWS account

Read

GenerateOrganizationsAccessReport

Grants permission to generate an access report for an AWS Organizations entity

access-report*

iam:OrganizationsPolicyId

Read

GenerateServiceLastAccessedDetails

Grants permission to generate a service last accessed data report for an IAM resource

group*

Read

policy*

aws:ResourceTag/${TagKey}

role*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

GetAccessKeyLastUsed

Grants permission to retrieve information about when the specified access key was last used

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Read

GetAccountAuthorizationDetails

Grants permission to retrieve information about all IAM users, groups, roles, and policies in your AWS account, including their relationships to one another

Read

GetAccountEmailAddress

Grants permission to retrieve the email address that is associated with the account

Read

GetAccountName

Grants permission to retrieve the account name that is associated with the account

Read

GetAccountPasswordPolicy

Grants permission to retrieve the password policy for the AWS account

Read

GetAccountProperties

Grants permission to retrieve account-level properties for IAM features

iam:AccountPropertyNamespaces

Read

GetAccountSummary

Grants permission to retrieve information about IAM entity usage and IAM quotas in the AWS account

List

GetCloudFrontPublicKey

Grants permission to retrieve information about the specified CloudFront public key

Read

GetContextKeysForCustomPolicy

Grants permission to retrieve a list of all of the context keys that are referenced in the specified policy

Read

GetContextKeysForPrincipalPolicy

Grants permission to retrieve a list of all context keys that are referenced in all IAM policies that are attached to the specified IAM identity (user, group, or role)

group

Read

role

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

user

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

GetCredentialReport

Grants permission to retrieve a credential report for the AWS account

Read

GetDelegationRequest

Retrieves information about a specific delegation request

delegation-request*

iam:DelegationRequestOwner

Read

GetGroup

Grants permission to retrieve a list of IAM users in the specified IAM group

group*

Read

GetGroupPolicy

Grants permission to retrieve an inline policy document that is embedded in the specified IAM group

group*

Read

GetHumanReadableSummary

Retrieves a human readable summary for a given entity. At this time, only delegation request are supported

delegation-request*

iam:DelegationRequestOwner

Read

GetInstanceProfile

Grants permission to retrieve information about the specified instance profile, including the instance profile's path, GUID, ARN, and role

instance-profile*

aws:ResourceTag/${TagKey}

Read

GetLoginProfile

Grants permission to retrieve the user name and password creation date for the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

List

GetMFADevice

Grants permission to retrieve information about an MFA device for the specified user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Read

GetOpenIDConnectProvider

Grants permission to retrieve information about the specified OpenID Connect (OIDC) provider resource in IAM

oidc-provider*

aws:ResourceTag/${TagKey}

Read

GetOrganizationsAccessReport

Grants permission to retrieve an AWS Organizations access report

Read

GetOutboundWebIdentityFederationInfo

Retrieves the configuration information for the outbound identity federation feature for the callers account

Read

GetPolicy

Grants permission to retrieve information about the specified managed policy, including the policy's default version and the total number of identities to which the policy is attached

policy*

aws:ResourceTag/${TagKey}

Read

GetPolicyVersion

Grants permission to retrieve information about a version of the specified managed policy, including the policy document

policy*

aws:ResourceTag/${TagKey}

Read

GetRole

Grants permission to retrieve information about the specified role, including the role's path, GUID, ARN, and the role's trust policy

role*

aws:ResourceTag/${TagKey}

iam:PermissionsBoundary

iam:ResourceTag/${TagKey}

iam:RoleTemplateARN

Read

GetRolePolicy

Grants permission to retrieve an inline policy document that is embedded with the specified IAM role

role*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Read

GetRoleTemplateVersion

Grants permission to retrieve information about a specific version of a role template

role-template*

Read

GetSAMLProvider

Grants permission to retrieve the SAML provider metadocument that was uploaded when the IAM SAML provider resource was created or updated

saml-provider*

aws:ResourceTag/${TagKey}

Read

GetSSHPublicKey

Grants permission to retrieve the specified SSH public key, including metadata about the key

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Read

GetServerCertificate

Grants permission to retrieve information about the specified server certificate stored in IAM

server-certificate*

aws:ResourceTag/${TagKey}

Read

GetServiceLastAccessedDetails

Grants permission to retrieve information about the service last accessed data report

Read

GetServiceLastAccessedDetailsWithEntities

Grants permission to retrieve information about the entities from the service last accessed data report

Read

GetServiceLinkedRoleDeletionStatus

Grants permission to retrieve an IAM service-linked role deletion status

role*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Read

GetUser

Grants permission to retrieve information about the specified IAM user, including the user's creation date, path, unique ID, and ARN

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Read

GetUserPolicy

Grants permission to retrieve an inline policy document that is embedded in the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Read

ListAccessKeys

Grants permission to list information about the access key IDs that are associated with the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

List

ListAccountAliases

Grants permission to list the account alias that is associated with the AWS account

List

ListAttachedGroupPolicies

Grants permission to list all managed policies that are attached to the specified IAM group

group*

List

ListAttachedRolePolicies

Grants permission to list all managed policies that are attached to the specified IAM role

role*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

List

ListAttachedUserPolicies

Grants permission to list all managed policies that are attached to the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

List

ListCloudFrontPublicKeys

Grants permission to list all current CloudFront public keys for the account

List

ListDelegationRequests

Lists delegation requests based on the specified criteria

iam:DelegationRequestOwner

List

ListEntitiesForPolicy

Grants permission to list all IAM identities to which the specified managed policy is attached

policy*

aws:ResourceTag/${TagKey}

List

ListGroupPolicies

Grants permission to list the names of the inline policies that are embedded in the specified IAM group

group*

List

ListGroups

Grants permission to list the IAM groups that have the specified path prefix

List

ListGroupsForUser

Grants permission to list the IAM groups that the specified IAM user belongs to

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

List

ListInstanceProfileTags

Grants permission to list the tags that are attached to the specified instance profile

instance-profile*

aws:ResourceTag/${TagKey}

List

ListInstanceProfiles

Grants permission to list the instance profiles that have the specified path prefix

List

ListInstanceProfilesForRole

Grants permission to list the instance profiles that have the specified associated IAM role

role*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

List

ListMFADeviceTags

Grants permission to list the tags that are attached to the specified virtual mfa device

mfa*

aws:ResourceTag/${TagKey}

List

ListMFADevices

Grants permission to list the MFA devices for an IAM user

user

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

List

ListOpenIDConnectProviderTags

Grants permission to list the tags that are attached to the specified OpenID Connect provider

oidc-provider*

aws:ResourceTag/${TagKey}

List

ListOpenIDConnectProviders

Grants permission to list information about the IAM OpenID Connect (OIDC) provider resource objects that are defined in the AWS account

List

ListOrganizationsFeatures

Grants permission to list the centralized root access features enabled for your organization

List

ListPolicies

Grants permission to list all managed policies

List

ListPoliciesGrantingServiceAccess

Grants permission to list information about the policies that grant an entity access to a specific service

group*

List

role*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

ListPolicyTags

Grants permission to list the tags that are attached to the specified managed policy

policy*

aws:ResourceTag/${TagKey}

List

ListPolicyVersions

Grants permission to list information about the versions of the specified managed policy, including the version that is currently set as the policy's default version

policy*

aws:ResourceTag/${TagKey}

List

ListRolePolicies

Grants permission to list the names of the inline policies that are embedded in the specified IAM role

role*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

List

ListRoleTags

Grants permission to list the tags that are attached to the specified IAM role

role*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

List

ListRoles

Grants permission to list the IAM roles that have the specified path prefix

List

ListSAMLProviderTags

Grants permission to list the tags that are attached to the specified SAML provider

saml-provider*

aws:ResourceTag/${TagKey}

List

ListSAMLProviders

Grants permission to list the SAML provider resources in IAM

List

ListSSHPublicKeys

Grants permission to list information about the SSH public keys that are associated with the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

List

ListSTSRegionalEndpointsStatus

Grants permission to list the status of all active STS regional endpoints

List

ListServerCertificateTags

Grants permission to list the tags that are attached to the specified server certificate

server-certificate*

aws:ResourceTag/${TagKey}

List

ListServerCertificates

Grants permission to list the server certificates that have the specified path prefix

List

ListServiceSpecificCredentials

Grants permission to list the service-specific credentials that are associated with the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

List

ListSigningCertificates

Grants permission to list information about the signing certificates that are associated with the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

List

ListUserPolicies

Grants permission to list the names of the inline policies that are embedded in the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

List

ListUserTags

Grants permission to list the tags that are attached to the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

List

ListUsers

Grants permission to list the IAM users that have the specified path prefix

List

ListVirtualMFADevices

Grants permission to list virtual MFA devices by assignment status

List

PutAccountProperties

Grants permission to set account-level properties for IAM features

iam:AccountPropertyNamespaces

Write

PutGroupPolicy

Grants permission to create or update an inline policy document that is embedded in the specified IAM group

group*

Permissions management, Write

PutRolePermissionsBoundary

Grants permission to set a managed policy as a permissions boundary for a role

role*

aws:ResourceTag/${TagKey}

iam:PermissionsBoundary

iam:ResourceTag/${TagKey}

iam:RoleTemplateARN

Permissions management, Write

PutRolePolicy

Grants permission to create or update an inline policy document that is embedded in the specified IAM role

role*

aws:ResourceTag/${TagKey}

iam:PermissionsBoundary

iam:ResourceTag/${TagKey}

iam:RoleTemplateARN

Permissions management, Write

PutUserPermissionsBoundary

Grants permission to set a managed policy as a permissions boundary for an IAM user

user*

aws:ResourceTag/${TagKey}

iam:PermissionsBoundary

iam:ResourceTag/${TagKey}

Permissions management, Write

PutUserPolicy

Grants permission to create or update an inline policy document that is embedded in the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:PermissionsBoundary

iam:ResourceTag/${TagKey}

Permissions management, Write

RejectDelegationRequest

Rejects a delegation request, denying the requested temporary access

delegation-request*

iam:DelegationRequestOwner

Write

RemoveClientIDFromOpenIDConnectProvider

Grants permission to remove the client ID (audience) from the list of client IDs in the specified IAM OpenID Connect (OIDC) provider resource

oidc-provider*

aws:ResourceTag/${TagKey}

Write

RemoveRoleFromInstanceProfile

Grants permission to remove an IAM role from the specified EC2 instance profile

instance-profile*

aws:ResourceTag/${TagKey}

Write

RemoveUserFromGroup

Grants permission to remove an IAM user from the specified group

group*

Write

ResetServiceSpecificCredential

Grants permission to reset the password for an existing service-specific credential for an IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

iam:ServiceSpecificCredentialServiceName

Write

ResyncMFADevice

Grants permission to synchronize the specified MFA device with its IAM entity (user or role)

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Write

SendDelegationToken

Sends the exchange token for an accepted delegation request

delegation-request*

iam:DelegationRequestOwner

Write

SetDefaultPolicyVersion

Grants permission to set the version of the specified policy as the policy's default version

policy*

aws:ResourceTag/${TagKey}

Permissions management, Write

SetSTSRegionalEndpointStatus

Grants permission to activate or deactivate an STS regional endpoint

Write

SetSecurityTokenServicePreferences

Grants permission to set the STS global endpoint token version

Write

SimulateCustomPolicy

Grants permission to simulate whether an identity-based policy or resource-based policy provides permissions for specific API operations and resources

Read

SimulatePrincipalPolicy

Grants permission to simulate whether an identity-based policy that is attached to a specified IAM entity (user or role) provides permissions for specific API operations and resources

group

Read

role

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

user

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

TagInstanceProfile

Grants permission to add tags to an instance profile

instance-profile*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Tagging, Write

TagMFADevice

Grants permission to add tags to a virtual mfa device

mfa*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Tagging, Write

TagOpenIDConnectProvider

Grants permission to add tags to an OpenID Connect provider

oidc-provider*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Tagging, Write

TagPolicy

Grants permission to add tags to a managed policy

policy*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Tagging, Write

TagRole

Grants permission to add tags to an IAM role

role*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

iam:ResourceTag/${TagKey}

iam:RoleTemplateARN

Tagging, Write

TagSAMLProvider

Grants permission to add tags to a SAML Provider

saml-provider*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Tagging, Write

TagServerCertificate

Grants permission to add tags to a server certificate

server-certificate*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Tagging, Write

TagUser

Grants permission to add tags to an IAM user

user*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

iam:ResourceTag/${TagKey}

Tagging, Write

UntagInstanceProfile

Grants permission to remove the specified tags from the instance profile

instance-profile*

aws:ResourceTag/${TagKey}

aws:TagKeys

Tagging, Write

UntagMFADevice

Grants permission to remove the specified tags from the virtual mfa device

mfa*

aws:ResourceTag/${TagKey}

aws:TagKeys

Tagging, Write

UntagOpenIDConnectProvider

Grants permission to remove the specified tags from the OpenID Connect provider

oidc-provider*

aws:ResourceTag/${TagKey}

aws:TagKeys

Tagging, Write

UntagPolicy

Grants permission to remove the specified tags from the managed policy

policy*

aws:ResourceTag/${TagKey}

aws:TagKeys

Tagging, Write

UntagRole

Grants permission to remove the specified tags from the role

role*

aws:ResourceTag/${TagKey}

aws:TagKeys

iam:ResourceTag/${TagKey}

Tagging, Write

UntagSAMLProvider

Grants permission to remove the specified tags from the SAML Provider

saml-provider*

aws:ResourceTag/${TagKey}

aws:TagKeys

Tagging, Write

UntagServerCertificate

Grants permission to remove the specified tags from the server certificate

server-certificate*

aws:ResourceTag/${TagKey}

aws:TagKeys

Tagging, Write

UntagUser

Grants permission to remove the specified tags from the user

user*

aws:ResourceTag/${TagKey}

aws:TagKeys

iam:ResourceTag/${TagKey}

Tagging, Write

UpdateAccessKey

Grants permission to update the status of the specified access key as Active or Inactive

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Write

UpdateAccountEmailAddress

Grants permission to update the email address that is associated with the account

Write

UpdateAccountName

Grants permission to update the account name that is associated with the account

Write

UpdateAccountPasswordPolicy

Grants permission to update the password policy settings for the AWS account

Write

UpdateAssumeRolePolicy

Grants permission to update the policy that grants an IAM entity permission to assume a role

role*

aws:ResourceTag/${TagKey}

iam:PermissionsBoundary

iam:ResourceTag/${TagKey}

Permissions management, Write

UpdateCloudFrontPublicKey

Grants permission to update an existing CloudFront public key

Write

UpdateGroup

Grants permission to update the name or path of the specified IAM group

group*

Write

UpdateLoginProfile

Grants permission to change the password for the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Write

UpdateOpenIDConnectProviderThumbprint

Grants permission to update the entire list of server certificate thumbprints that are associated with an OpenID Connect (OIDC) provider resource

oidc-provider*

aws:ResourceTag/${TagKey}

Write

UpdateRole

Grants permission to update the description or maximum session duration setting of a role

role*

aws:ResourceTag/${TagKey}

iam:PermissionsBoundary

iam:ResourceTag/${TagKey}

Write

UpdateRoleDescription

Grants permission to update only the description of a role

role*

aws:ResourceTag/${TagKey}

iam:PermissionsBoundary

iam:ResourceTag/${TagKey}

Write

UpdateSAMLProvider

Grants permission to update the metadata document for an existing SAML provider resource

saml-provider*

aws:ResourceTag/${TagKey}

Write

UpdateSSHPublicKey

Grants permission to update the status of an IAM user's SSH public key to active or inactive

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Write

UpdateServerCertificate

Grants permission to update the name or the path of the specified server certificate stored in IAM

server-certificate*

aws:ResourceTag/${TagKey}

Write

UpdateServiceSpecificCredential

Grants permission to update the status of a service-specific credential to active or inactive for an IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

iam:ServiceSpecificCredentialServiceName

Write

UpdateSigningCertificate

Grants permission to update the status of the specified user signing certificate to active or disabled

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Write

UpdateUser

Grants permission to update the name or the path of the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Write

UploadCloudFrontPublicKey

Grants permission to upload a CloudFront public key

Write

UploadSSHPublicKey

Grants permission to upload an SSH public key and associate it with the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Write

UploadServerCertificate

Grants permission to upload a server certificate entity for the AWS account

server-certificate*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

UploadSigningCertificate

Grants permission to upload an X.509 signing certificate and associate it with the specified IAM user

user*

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Write

Permission-only actions for AWS Identity and Access Management (IAM)

The following actions are defined by AWS Identity and Access Management (IAM) but are not directly invocable through any API operation. They can only be used in IAM policy statements to grant or deny permissions.

Actions Description Resource types (*required) Condition keys Access level

PassRole

Grants permission to pass a role to a service

role*

aws:ResourceTag/${TagKey}

iam:AssociatedResourceArn

iam:PassedToService

iam:ResourceTag/${TagKey}

Write

Resource types defined by AWS Identity and Access Management (IAM)

The following resource types are defined by this service and can be used in the Resource element of IAM permission policy statements.

Resource types ARN Condition keys

access-report

arn:${Partition}:iam::${Account}:access-report/${EntityPath}

assumed-role

arn:${Partition}:iam::${Account}:assumed-role/${RoleName}/${RoleSessionName}

delegation-request

arn:${Partition}:iam::${Account}:delegation-request/${DelegationRequestId}

iam:DelegationRequestOwner

federated-user

arn:${Partition}:iam::${Account}:federated-user/${UserName}

group

arn:${Partition}:iam::${Account}:group/${GroupNameWithPath}

instance-profile

arn:${Partition}:iam::${Account}:instance-profile/${InstanceProfileNameWithPath}

aws:ResourceTag/${TagKey}

mfa

arn:${Partition}:iam::${Account}:mfa/${MfaTokenIdWithPath}

aws:ResourceTag/${TagKey}

oidc-provider

arn:${Partition}:iam::${Account}:oidc-provider/${OidcProviderName}

aws:ResourceTag/${TagKey}

policy

arn:${Partition}:iam::${Account}:policy/${PolicyNameWithPath}

aws:ResourceTag/${TagKey}

role

arn:${Partition}:iam::${Account}:role/${RoleNameWithPath}

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

role-template

arn:${Partition}:iam::aws:role-template/${AWSServicePrincipal}/${RoleTemplateName}:${RoleTemplateMajorVersion}

saml-provider

arn:${Partition}:iam::${Account}:saml-provider/${SamlProviderName}

aws:ResourceTag/${TagKey}

server-certificate

arn:${Partition}:iam::${Account}:server-certificate/${CertificateNameWithPath}

aws:ResourceTag/${TagKey}

sms-mfa

arn:${Partition}:iam::${Account}:sms-mfa/${MfaTokenIdWithPath}

user

arn:${Partition}:iam::${Account}:user/${UserNameWithPath}

aws:ResourceTag/${TagKey}

iam:ResourceTag/${TagKey}

Condition keys for AWS Identity and Access Management (IAM)

AWS Identity and Access Management (IAM) defines the following condition keys that can be used in the Condition element of an IAM policy.

Condition keys Description Type

aws:RequestTag/${TagKey}

Filters access based on the tags that are passed in the request

String

aws:ResourceTag/${TagKey}

Filters access based on the tags associated with the resource

String

aws:TagKeys

Filters access based on the tag keys that are passed in the request

ArrayOfString

iam:AWSServiceName

Filters access by the AWS service to which this role is attached

String

iam:AccountPropertyNamespaces

Filters access by the account property namespaces being read or modified

ArrayOfString

iam:AssociatedResourceArn

Filters access by the resource that the role will be used on behalf of

ARN

iam:DelegationDuration

Filters access based on the requested delegation duration

String

iam:DelegationRequestOwner

Filters access based on the delegation request owner

ARN

iam:FIDO-FIPS-140-2-certification

Filters access by the MFA device FIPS-140-2 validation certification level at the time of registration of a FIDO security key

String

iam:FIDO-FIPS-140-3-certification

Filters access by the MFA device FIPS-140-3 validation certification level at the time of registration of a FIDO security key

String

iam:FIDO-certification

Filters access by the MFA device FIDO certification level at the time of registration of a FIDO security key

String

iam:NotificationChannel

Filters access based on the requested notification channel

String

iam:OrganizationsPolicyId

Filters access by the ID of an AWS Organizations policy

String

iam:PassedToService

Filters access by the AWS service to which this role is passed

String

iam:PermissionsBoundary

Filters access if the specified policy is set as the permissions boundary on the IAM entity (user or role)

ARN

iam:PolicyARN

Filters access by the ARN of an IAM policy

ARN

iam:RegisterSecurityKey

Filters access by the current state of MFA device enablement

String

iam:ResourceTag/${TagKey}

Filters access by the tags attached to an IAM entity (user or role)

String

iam:RoleTemplateARN

Filters access by the role template ARN used in the request

ARN

iam:ServiceSpecificCredentialAgeDays

Filters access by the duration until the credential's expiration

Numeric

iam:ServiceSpecificCredentialServiceName

Filters access by the service associated with the credential

String

iam:TemplateArn

Filters access based on the requested template ARN

ARN