iam

187 actions in the iam service. Select an action to see its access level, resource ARNs, condition keys, and a copy-paste IAM policy.

iam:AcceptDelegationRequest

Write

Accepts a delegation request resource, granting the requested temporary access

iam:AddClientIDToOpenIDConnectProvider

Write

Grants permission to add a new client ID (audience) to the list of registered IDs for the specified IAM OpenID Connect (OIDC) provider resource

iam:AddRoleToInstanceProfile

Write

Grants permission to add an IAM role to the specified instance profile

iam:AddUserToGroup

Write

Grants permission to add an IAM user to the specified IAM group

iam:AssociateDelegationRequest

Write

Associates a delegation request resource with the calling identity

iam:AttachGroupPolicy

Permissions management

Grants permission to attach a managed policy to the specified IAM group

iam:AttachRolePolicy

Permissions management

Grants permission to attach a managed policy to the specified IAM role

iam:AttachUserPolicy

Permissions management

Grants permission to attach a managed policy to the specified IAM user

iam:ChangePassword

Write

Grants permission to an IAM user to change their own password

iam:CreateAccessKey

Write

Grants permission to create access key and secret access key for the specified IAM user

iam:CreateAccountAlias

Write

Grants permission to create an alias for your AWS account

iam:CreateDelegationRequest

Write

Creates an IAM delegation request resource for temporary access delegation

iam:CreateGroup

Write

Grants permission to create a new group

iam:CreateInstanceProfile

Write

Grants permission to create a new instance profile

iam:CreateLoginProfile

Write

Grants permission to create a password for the specified IAM user

iam:CreateOpenIDConnectProvider

Write

Grants permission to create an IAM resource that describes an identity provider (IdP) that supports OpenID Connect (OIDC)

iam:CreatePolicy

Permissions management

Grants permission to create a new managed policy

iam:CreatePolicyVersion

Permissions management

Grants permission to create a new version of the specified managed policy

iam:CreateRole

Write

Grants permission to create a new role

iam:CreateSAMLProvider

Write

Grants permission to create an IAM resource that describes an identity provider (IdP) that supports SAML 2.0

iam:CreateServiceLinkedRole

Write

Grants permission to create an IAM role that allows an AWS service to perform actions on your behalf

iam:CreateServiceSpecificCredential

Write

Grants permission to create a new service-specific credential for an IAM user

iam:CreateUser

Write

Grants permission to create a new IAM user

iam:CreateVirtualMFADevice

Write

Grants permission to create a new virtual MFA device

iam:DeactivateMFADevice

Write

Grants permission to deactivate the specified MFA device and remove its association with the IAM user for which it was originally enabled

iam:DeleteAccessKey

Write

Grants permission to delete the access key pair that is associated with the specified IAM user

iam:DeleteAccountAlias

Write

Grants permission to delete the specified AWS account alias

iam:DeleteAccountPasswordPolicy

Permissions management

Grants permission to delete the password policy for the AWS account

iam:DeleteCloudFrontPublicKey

Write

Grants permission to delete an existing CloudFront public key

iam:DeleteGroup

Write

Grants permission to delete the specified IAM group

iam:DeleteGroupPolicy

Permissions management

Grants permission to delete the specified inline policy from its group

iam:DeleteInstanceProfile

Write

Grants permission to delete the specified instance profile

iam:DeleteLoginProfile

Write

Grants permission to delete the password for the specified IAM user

iam:DeleteOpenIDConnectProvider

Write

Grants permission to delete an OpenID Connect identity provider (IdP) resource object in IAM

iam:DeletePolicy

Permissions management

Grants permission to delete the specified managed policy and remove it from any IAM entities (users, groups, or roles) to which it is attached

iam:DeletePolicyVersion

Permissions management

Grants permission to delete a version from the specified managed policy

iam:DeleteRole

Write

Grants permission to delete the specified role

iam:DeleteRolePermissionsBoundary

Permissions management

Grants permission to remove the permissions boundary from a role

iam:DeleteRolePolicy

Permissions management

Grants permission to delete the specified inline policy from the specified role

iam:DeleteSAMLProvider

Write

Grants permission to delete a SAML provider resource in IAM

iam:DeleteServerCertificate

Write

Grants permission to delete the specified server certificate

iam:DeleteServiceLinkedRole

Write

Grants permission to delete an IAM role that is linked to a specific AWS service, if the service is no longer using it

iam:DeleteServiceSpecificCredential

Write

Grants permission to delete the specified service-specific credential for an IAM user

iam:DeleteSigningCertificate

Write

Grants permission to delete a signing certificate that is associated with the specified IAM user

iam:DeleteSSHPublicKey

Write

Grants permission to delete the specified SSH public key

iam:DeleteUser

Write

Grants permission to delete the specified IAM user

iam:DeleteUserPermissionsBoundary

Permissions management

Grants permission to remove the permissions boundary from the specified IAM user

iam:DeleteUserPolicy

Permissions management

Grants permission to delete the specified inline policy from an IAM user

iam:DeleteVirtualMFADevice

Write

Grants permission to delete a virtual MFA device

iam:DetachGroupPolicy

Permissions management

Grants permission to detach a managed policy from the specified IAM group

iam:DetachRolePolicy

Permissions management

Grants permission to detach a managed policy from the specified role

iam:DetachUserPolicy

Permissions management

Grants permission to detach a managed policy from the specified IAM user

iam:DisableOrganizationsRootCredentialsManagement

Write

Grants permission to disable the management of member account root user credentials for an organization managed under the current account

iam:DisableOrganizationsRootSessions

Write

Grants permission to disable privileged root actions in member accounts for an organization managed under the current account

iam:DisableOutboundWebIdentityFederation

Write

Disables the outbound identity federation feature for the callers account

iam:EnableMFADevice

Write

Grants permission to enable an MFA device and associate it with the specified IAM user

iam:EnableOrganizationsRootCredentialsManagement

Write

Grants permission to enable the management of member account root user credentials for an organization managed under the current account

iam:EnableOrganizationsRootSessions

Write

Grants permission to enable privileged root actions in member accounts for an organization managed under the current account

iam:EnableOutboundWebIdentityFederation

Write

Enables the outbound identity federation feature for the callers account

iam:GenerateCredentialReport

Read

Grants permission to generate a credential report for the AWS account

iam:GenerateOrganizationsAccessReport

Read

Grants permission to generate an access report for an AWS Organizations entity

iam:GenerateServiceLastAccessedDetails

Read

Grants permission to generate a service last accessed data report for an IAM resource

iam:GetAccessKeyLastUsed

Read

Grants permission to retrieve information about when the specified access key was last used

iam:GetAccountAuthorizationDetails

Read

Grants permission to retrieve information about all IAM users, groups, roles, and policies in your AWS account, including their relationships to one another

iam:GetAccountEmailAddress

Read

Grants permission to retrieve the email address that is associated with the account

iam:GetAccountName

Read

Grants permission to retrieve the account name that is associated with the account

iam:GetAccountPasswordPolicy

Read

Grants permission to retrieve the password policy for the AWS account

iam:GetAccountSummary

List

Grants permission to retrieve information about IAM entity usage and IAM quotas in the AWS account

iam:GetCloudFrontPublicKey

Read

Grants permission to retrieve information about the specified CloudFront public key

iam:GetContextKeysForCustomPolicy

Read

Grants permission to retrieve a list of all of the context keys that are referenced in the specified policy

iam:GetContextKeysForPrincipalPolicy

Read

Grants permission to retrieve a list of all context keys that are referenced in all IAM policies that are attached to the specified IAM identity (user, group, or role)

iam:GetCredentialReport

Read

Grants permission to retrieve a credential report for the AWS account

iam:GetDelegationRequest

Read

Retrieves information about a specific delegation request

iam:GetGroup

Read

Grants permission to retrieve a list of IAM users in the specified IAM group

iam:GetGroupPolicy

Read

Grants permission to retrieve an inline policy document that is embedded in the specified IAM group

iam:GetHumanReadableSummary

Read

Retrieves a human readable summary for a given entity. At this time, only delegation request are supported

iam:GetInstanceProfile

Read

Grants permission to retrieve information about the specified instance profile, including the instance profile's path, GUID, ARN, and role

iam:GetLoginProfile

List

Grants permission to retrieve the user name and password creation date for the specified IAM user

iam:GetMFADevice

Read

Grants permission to retrieve information about an MFA device for the specified user

iam:GetOpenIDConnectProvider

Read

Grants permission to retrieve information about the specified OpenID Connect (OIDC) provider resource in IAM

iam:GetOrganizationsAccessReport

Read

Grants permission to retrieve an AWS Organizations access report

iam:GetOutboundWebIdentityFederationInfo

Read

Retrieves the configuration information for the outbound identity federation feature for the callers account

iam:GetPolicy

Read

Grants permission to retrieve information about the specified managed policy, including the policy's default version and the total number of identities to which the policy is attached

iam:GetPolicyVersion

Read

Grants permission to retrieve information about a version of the specified managed policy, including the policy document

iam:GetRole

Read

Grants permission to retrieve information about the specified role, including the role's path, GUID, ARN, and the role's trust policy

iam:GetRolePolicy

Read

Grants permission to retrieve an inline policy document that is embedded with the specified IAM role

iam:GetSAMLProvider

Read

Grants permission to retrieve the SAML provider metadocument that was uploaded when the IAM SAML provider resource was created or updated

iam:GetServerCertificate

Read

Grants permission to retrieve information about the specified server certificate stored in IAM

iam:GetServiceLastAccessedDetails

Read

Grants permission to retrieve information about the service last accessed data report

iam:GetServiceLastAccessedDetailsWithEntities

Read

Grants permission to retrieve information about the entities from the service last accessed data report

iam:GetServiceLinkedRoleDeletionStatus

Read

Grants permission to retrieve an IAM service-linked role deletion status

iam:GetSSHPublicKey

Read

Grants permission to retrieve the specified SSH public key, including metadata about the key

iam:GetUser

Read

Grants permission to retrieve information about the specified IAM user, including the user's creation date, path, unique ID, and ARN

iam:GetUserPolicy

Read

Grants permission to retrieve an inline policy document that is embedded in the specified IAM user

iam:ListAccessKeys

List

Grants permission to list information about the access key IDs that are associated with the specified IAM user

iam:ListAccountAliases

List

Grants permission to list the account alias that is associated with the AWS account

iam:ListAttachedGroupPolicies

List

Grants permission to list all managed policies that are attached to the specified IAM group

iam:ListAttachedRolePolicies

List

Grants permission to list all managed policies that are attached to the specified IAM role

iam:ListAttachedUserPolicies

List

Grants permission to list all managed policies that are attached to the specified IAM user

iam:ListCloudFrontPublicKeys

List

Grants permission to list all current CloudFront public keys for the account

iam:ListDelegationRequests

List

Lists delegation requests based on the specified criteria

iam:ListEntitiesForPolicy

List

Grants permission to list all IAM identities to which the specified managed policy is attached

iam:ListGroupPolicies

List

Grants permission to list the names of the inline policies that are embedded in the specified IAM group

iam:ListGroups

List

Grants permission to list the IAM groups that have the specified path prefix

iam:ListGroupsForUser

List

Grants permission to list the IAM groups that the specified IAM user belongs to

iam:ListInstanceProfiles

List

Grants permission to list the instance profiles that have the specified path prefix

iam:ListInstanceProfilesForRole

List

Grants permission to list the instance profiles that have the specified associated IAM role

iam:ListInstanceProfileTags

List

Grants permission to list the tags that are attached to the specified instance profile

iam:ListMFADevices

List

Grants permission to list the MFA devices for an IAM user

iam:ListMFADeviceTags

List

Grants permission to list the tags that are attached to the specified virtual mfa device

iam:ListOpenIDConnectProviders

List

Grants permission to list information about the IAM OpenID Connect (OIDC) provider resource objects that are defined in the AWS account

iam:ListOpenIDConnectProviderTags

List

Grants permission to list the tags that are attached to the specified OpenID Connect provider

iam:ListOrganizationsFeatures

List

Grants permission to list the centralized root access features enabled for your organization

iam:ListPolicies

List

Grants permission to list all managed policies

iam:ListPoliciesGrantingServiceAccess

List

Grants permission to list information about the policies that grant an entity access to a specific service

iam:ListPolicyTags

List

Grants permission to list the tags that are attached to the specified managed policy

iam:ListPolicyVersions

List

Grants permission to list information about the versions of the specified managed policy, including the version that is currently set as the policy's default version

iam:ListRolePolicies

List

Grants permission to list the names of the inline policies that are embedded in the specified IAM role

iam:ListRoles

List

Grants permission to list the IAM roles that have the specified path prefix

iam:ListRoleTags

List

Grants permission to list the tags that are attached to the specified IAM role

iam:ListSAMLProviders

List

Grants permission to list the SAML provider resources in IAM

iam:ListSAMLProviderTags

List

Grants permission to list the tags that are attached to the specified SAML provider

iam:ListServerCertificates

List

Grants permission to list the server certificates that have the specified path prefix

iam:ListServerCertificateTags

List

Grants permission to list the tags that are attached to the specified server certificate

iam:ListServiceSpecificCredentials

List

Grants permission to list the service-specific credentials that are associated with the specified IAM user

iam:ListSigningCertificates

List

Grants permission to list information about the signing certificates that are associated with the specified IAM user

iam:ListSSHPublicKeys

List

Grants permission to list information about the SSH public keys that are associated with the specified IAM user

iam:ListSTSRegionalEndpointsStatus

List

Grants permission to list the status of all active STS regional endpoints

iam:ListUserPolicies

List

Grants permission to list the names of the inline policies that are embedded in the specified IAM user

iam:ListUsers

List

Grants permission to list the IAM users that have the specified path prefix

iam:ListUserTags

List

Grants permission to list the tags that are attached to the specified IAM user

iam:ListVirtualMFADevices

List

Grants permission to list virtual MFA devices by assignment status

iam:PassRole

Write

Grants permission to pass a role to a service

iam:PutGroupPolicy

Permissions management

Grants permission to create or update an inline policy document that is embedded in the specified IAM group

iam:PutRolePermissionsBoundary

Permissions management

Grants permission to set a managed policy as a permissions boundary for a role

iam:PutRolePolicy

Permissions management

Grants permission to create or update an inline policy document that is embedded in the specified IAM role

iam:PutUserPermissionsBoundary

Permissions management

Grants permission to set a managed policy as a permissions boundary for an IAM user

iam:PutUserPolicy

Permissions management

Grants permission to create or update an inline policy document that is embedded in the specified IAM user

iam:RejectDelegationRequest

Write

Rejects a delegation request, denying the requested temporary access

iam:RemoveClientIDFromOpenIDConnectProvider

Write

Grants permission to remove the client ID (audience) from the list of client IDs in the specified IAM OpenID Connect (OIDC) provider resource

iam:RemoveRoleFromInstanceProfile

Write

Grants permission to remove an IAM role from the specified EC2 instance profile

iam:RemoveUserFromGroup

Write

Grants permission to remove an IAM user from the specified group

iam:ResetServiceSpecificCredential

Write

Grants permission to reset the password for an existing service-specific credential for an IAM user

iam:ResyncMFADevice

Write

Grants permission to synchronize the specified MFA device with its IAM entity (user or role)

iam:SendDelegationToken

Write

Sends the exchange token for an accepted delegation request

iam:SetDefaultPolicyVersion

Permissions management

Grants permission to set the version of the specified policy as the policy's default version

iam:SetSecurityTokenServicePreferences

Write

Grants permission to set the STS global endpoint token version

iam:SetSTSRegionalEndpointStatus

Write

Grants permission to activate or deactivate an STS regional endpoint

iam:SimulateCustomPolicy

Read

Grants permission to simulate whether an identity-based policy or resource-based policy provides permissions for specific API operations and resources

iam:SimulatePrincipalPolicy

Read

Grants permission to simulate whether an identity-based policy that is attached to a specified IAM entity (user or role) provides permissions for specific API operations and resources

iam:TagInstanceProfile

Tagging

Grants permission to add tags to an instance profile

iam:TagMFADevice

Tagging

Grants permission to add tags to a virtual mfa device

iam:TagOpenIDConnectProvider

Tagging

Grants permission to add tags to an OpenID Connect provider

iam:TagPolicy

Tagging

Grants permission to add tags to a managed policy

iam:TagRole

Tagging

Grants permission to add tags to an IAM role

iam:TagSAMLProvider

Tagging

Grants permission to add tags to a SAML Provider

iam:TagServerCertificate

Tagging

Grants permission to add tags to a server certificate

iam:TagUser

Tagging

Grants permission to add tags to an IAM user

iam:UntagInstanceProfile

Tagging

Grants permission to remove the specified tags from the instance profile

iam:UntagMFADevice

Tagging

Grants permission to remove the specified tags from the virtual mfa device

iam:UntagOpenIDConnectProvider

Tagging

Grants permission to remove the specified tags from the OpenID Connect provider

iam:UntagPolicy

Tagging

Grants permission to remove the specified tags from the managed policy

iam:UntagRole

Tagging

Grants permission to remove the specified tags from the role

iam:UntagSAMLProvider

Tagging

Grants permission to remove the specified tags from the SAML Provider

iam:UntagServerCertificate

Tagging

Grants permission to remove the specified tags from the server certificate

iam:UntagUser

Tagging

Grants permission to remove the specified tags from the user

iam:UpdateAccessKey

Write

Grants permission to update the status of the specified access key as Active or Inactive

iam:UpdateAccountEmailAddress

Write

Grants permission to update the email address that is associated with the account

iam:UpdateAccountName

Write

Grants permission to update the account name that is associated with the account

iam:UpdateAccountPasswordPolicy

Write

Grants permission to update the password policy settings for the AWS account

iam:UpdateAssumeRolePolicy

Permissions management

Grants permission to update the policy that grants an IAM entity permission to assume a role

iam:UpdateCloudFrontPublicKey

Write

Grants permission to update an existing CloudFront public key

iam:UpdateGroup

Write

Grants permission to update the name or path of the specified IAM group

iam:UpdateLoginProfile

Write

Grants permission to change the password for the specified IAM user

iam:UpdateOpenIDConnectProviderThumbprint

Write

Grants permission to update the entire list of server certificate thumbprints that are associated with an OpenID Connect (OIDC) provider resource

iam:UpdateRole

Write

Grants permission to update the description or maximum session duration setting of a role

iam:UpdateRoleDescription

Write

Grants permission to update only the description of a role

iam:UpdateSAMLProvider

Write

Grants permission to update the metadata document for an existing SAML provider resource

iam:UpdateServerCertificate

Write

Grants permission to update the name or the path of the specified server certificate stored in IAM

iam:UpdateServiceSpecificCredential

Write

Grants permission to update the status of a service-specific credential to active or inactive for an IAM user

iam:UpdateSigningCertificate

Write

Grants permission to update the status of the specified user signing certificate to active or disabled

iam:UpdateSSHPublicKey

Write

Grants permission to update the status of an IAM user's SSH public key to active or inactive

iam:UpdateUser

Write

Grants permission to update the name or the path of the specified IAM user

iam:UploadCloudFrontPublicKey

Write

Grants permission to upload a CloudFront public key

iam:UploadServerCertificate

Write

Grants permission to upload a server certificate entity for the AWS account

iam:UploadSigningCertificate

Write

Grants permission to upload an X.509 signing certificate and associate it with the specified IAM user

iam:UploadSSHPublicKey

Write

Grants permission to upload an SSH public key and associate it with the specified IAM user