187 actions in the iam service. Select an action to see its access level, resource ARNs, condition keys, and a copy-paste IAM policy.
Accepts a delegation request resource, granting the requested temporary access
Grants permission to add a new client ID (audience) to the list of registered IDs for the specified IAM OpenID Connect (OIDC) provider resource
Grants permission to add an IAM role to the specified instance profile
Grants permission to add an IAM user to the specified IAM group
Associates a delegation request resource with the calling identity
Grants permission to attach a managed policy to the specified IAM group
Grants permission to attach a managed policy to the specified IAM role
Grants permission to attach a managed policy to the specified IAM user
Grants permission to an IAM user to change their own password
Grants permission to create access key and secret access key for the specified IAM user
Grants permission to create an alias for your AWS account
Creates an IAM delegation request resource for temporary access delegation
Grants permission to create a new group
Grants permission to create a new instance profile
Grants permission to create a password for the specified IAM user
Grants permission to create an IAM resource that describes an identity provider (IdP) that supports OpenID Connect (OIDC)
Grants permission to create a new managed policy
Grants permission to create a new version of the specified managed policy
Grants permission to create a new role
Grants permission to create an IAM resource that describes an identity provider (IdP) that supports SAML 2.0
Grants permission to create an IAM role that allows an AWS service to perform actions on your behalf
Grants permission to create a new service-specific credential for an IAM user
Grants permission to create a new IAM user
Grants permission to create a new virtual MFA device
Grants permission to deactivate the specified MFA device and remove its association with the IAM user for which it was originally enabled
Grants permission to delete the access key pair that is associated with the specified IAM user
Grants permission to delete the specified AWS account alias
Grants permission to delete the password policy for the AWS account
Grants permission to delete an existing CloudFront public key
Grants permission to delete the specified IAM group
Grants permission to delete the specified inline policy from its group
Grants permission to delete the specified instance profile
Grants permission to delete the password for the specified IAM user
Grants permission to delete an OpenID Connect identity provider (IdP) resource object in IAM
Grants permission to delete the specified managed policy and remove it from any IAM entities (users, groups, or roles) to which it is attached
Grants permission to delete a version from the specified managed policy
Grants permission to delete the specified role
Grants permission to remove the permissions boundary from a role
Grants permission to delete the specified inline policy from the specified role
Grants permission to delete a SAML provider resource in IAM
Grants permission to delete the specified server certificate
Grants permission to delete an IAM role that is linked to a specific AWS service, if the service is no longer using it
Grants permission to delete the specified service-specific credential for an IAM user
Grants permission to delete a signing certificate that is associated with the specified IAM user
Grants permission to delete the specified SSH public key
Grants permission to delete the specified IAM user
Grants permission to remove the permissions boundary from the specified IAM user
Grants permission to delete the specified inline policy from an IAM user
Grants permission to delete a virtual MFA device
Grants permission to detach a managed policy from the specified IAM group
Grants permission to detach a managed policy from the specified role
Grants permission to detach a managed policy from the specified IAM user
Grants permission to disable the management of member account root user credentials for an organization managed under the current account
Grants permission to disable privileged root actions in member accounts for an organization managed under the current account
Disables the outbound identity federation feature for the callers account
Grants permission to enable an MFA device and associate it with the specified IAM user
Grants permission to enable the management of member account root user credentials for an organization managed under the current account
Grants permission to enable privileged root actions in member accounts for an organization managed under the current account
Enables the outbound identity federation feature for the callers account
Grants permission to generate a credential report for the AWS account
Grants permission to generate an access report for an AWS Organizations entity
Grants permission to generate a service last accessed data report for an IAM resource
Grants permission to retrieve information about when the specified access key was last used
Grants permission to retrieve information about all IAM users, groups, roles, and policies in your AWS account, including their relationships to one another
Grants permission to retrieve the email address that is associated with the account
Grants permission to retrieve the account name that is associated with the account
Grants permission to retrieve the password policy for the AWS account
Grants permission to retrieve information about IAM entity usage and IAM quotas in the AWS account
Grants permission to retrieve information about the specified CloudFront public key
Grants permission to retrieve a list of all of the context keys that are referenced in the specified policy
Grants permission to retrieve a list of all context keys that are referenced in all IAM policies that are attached to the specified IAM identity (user, group, or role)
Grants permission to retrieve a credential report for the AWS account
Retrieves information about a specific delegation request
Grants permission to retrieve a list of IAM users in the specified IAM group
Grants permission to retrieve an inline policy document that is embedded in the specified IAM group
Retrieves a human readable summary for a given entity. At this time, only delegation request are supported
Grants permission to retrieve information about the specified instance profile, including the instance profile's path, GUID, ARN, and role
Grants permission to retrieve the user name and password creation date for the specified IAM user
Grants permission to retrieve information about an MFA device for the specified user
Grants permission to retrieve information about the specified OpenID Connect (OIDC) provider resource in IAM
Grants permission to retrieve an AWS Organizations access report
Retrieves the configuration information for the outbound identity federation feature for the callers account
Grants permission to retrieve information about the specified managed policy, including the policy's default version and the total number of identities to which the policy is attached
Grants permission to retrieve information about a version of the specified managed policy, including the policy document
Grants permission to retrieve information about the specified role, including the role's path, GUID, ARN, and the role's trust policy
Grants permission to retrieve an inline policy document that is embedded with the specified IAM role
Grants permission to retrieve the SAML provider metadocument that was uploaded when the IAM SAML provider resource was created or updated
Grants permission to retrieve information about the specified server certificate stored in IAM
Grants permission to retrieve information about the service last accessed data report
Grants permission to retrieve information about the entities from the service last accessed data report
Grants permission to retrieve an IAM service-linked role deletion status
Grants permission to retrieve the specified SSH public key, including metadata about the key
Grants permission to retrieve information about the specified IAM user, including the user's creation date, path, unique ID, and ARN
Grants permission to retrieve an inline policy document that is embedded in the specified IAM user
Grants permission to list information about the access key IDs that are associated with the specified IAM user
Grants permission to list the account alias that is associated with the AWS account
Grants permission to list all managed policies that are attached to the specified IAM group
Grants permission to list all managed policies that are attached to the specified IAM role
Grants permission to list all managed policies that are attached to the specified IAM user
Grants permission to list all current CloudFront public keys for the account
Lists delegation requests based on the specified criteria
Grants permission to list all IAM identities to which the specified managed policy is attached
Grants permission to list the names of the inline policies that are embedded in the specified IAM group
Grants permission to list the IAM groups that have the specified path prefix
Grants permission to list the IAM groups that the specified IAM user belongs to
Grants permission to list the instance profiles that have the specified path prefix
Grants permission to list the instance profiles that have the specified associated IAM role
Grants permission to list the tags that are attached to the specified instance profile
Grants permission to list the MFA devices for an IAM user
Grants permission to list the tags that are attached to the specified virtual mfa device
Grants permission to list information about the IAM OpenID Connect (OIDC) provider resource objects that are defined in the AWS account
Grants permission to list the tags that are attached to the specified OpenID Connect provider
Grants permission to list the centralized root access features enabled for your organization
Grants permission to list all managed policies
Grants permission to list information about the policies that grant an entity access to a specific service
Grants permission to list the tags that are attached to the specified managed policy
Grants permission to list information about the versions of the specified managed policy, including the version that is currently set as the policy's default version
Grants permission to list the names of the inline policies that are embedded in the specified IAM role
Grants permission to list the IAM roles that have the specified path prefix
Grants permission to list the tags that are attached to the specified IAM role
Grants permission to list the SAML provider resources in IAM
Grants permission to list the tags that are attached to the specified SAML provider
Grants permission to list the server certificates that have the specified path prefix
Grants permission to list the tags that are attached to the specified server certificate
Grants permission to list the service-specific credentials that are associated with the specified IAM user
Grants permission to list information about the signing certificates that are associated with the specified IAM user
Grants permission to list information about the SSH public keys that are associated with the specified IAM user
Grants permission to list the status of all active STS regional endpoints
Grants permission to list the names of the inline policies that are embedded in the specified IAM user
Grants permission to list the IAM users that have the specified path prefix
Grants permission to list the tags that are attached to the specified IAM user
Grants permission to list virtual MFA devices by assignment status
Grants permission to pass a role to a service
Grants permission to create or update an inline policy document that is embedded in the specified IAM group
Grants permission to set a managed policy as a permissions boundary for a role
Grants permission to create or update an inline policy document that is embedded in the specified IAM role
Grants permission to set a managed policy as a permissions boundary for an IAM user
Grants permission to create or update an inline policy document that is embedded in the specified IAM user
Rejects a delegation request, denying the requested temporary access
Grants permission to remove the client ID (audience) from the list of client IDs in the specified IAM OpenID Connect (OIDC) provider resource
Grants permission to remove an IAM role from the specified EC2 instance profile
Grants permission to remove an IAM user from the specified group
Grants permission to reset the password for an existing service-specific credential for an IAM user
Grants permission to synchronize the specified MFA device with its IAM entity (user or role)
Sends the exchange token for an accepted delegation request
Grants permission to set the version of the specified policy as the policy's default version
Grants permission to set the STS global endpoint token version
Grants permission to activate or deactivate an STS regional endpoint
Grants permission to simulate whether an identity-based policy or resource-based policy provides permissions for specific API operations and resources
Grants permission to simulate whether an identity-based policy that is attached to a specified IAM entity (user or role) provides permissions for specific API operations and resources
Grants permission to add tags to an instance profile
Grants permission to add tags to a virtual mfa device
Grants permission to add tags to an OpenID Connect provider
Grants permission to add tags to a managed policy
Grants permission to add tags to an IAM role
Grants permission to add tags to a SAML Provider
Grants permission to add tags to a server certificate
Grants permission to add tags to an IAM user
Grants permission to remove the specified tags from the instance profile
Grants permission to remove the specified tags from the virtual mfa device
Grants permission to remove the specified tags from the OpenID Connect provider
Grants permission to remove the specified tags from the managed policy
Grants permission to remove the specified tags from the role
Grants permission to remove the specified tags from the SAML Provider
Grants permission to remove the specified tags from the server certificate
Grants permission to remove the specified tags from the user
Grants permission to update the status of the specified access key as Active or Inactive
Grants permission to update the email address that is associated with the account
Grants permission to update the account name that is associated with the account
Grants permission to update the password policy settings for the AWS account
Grants permission to update the policy that grants an IAM entity permission to assume a role
Grants permission to update an existing CloudFront public key
Grants permission to update the name or path of the specified IAM group
Grants permission to change the password for the specified IAM user
Grants permission to update the entire list of server certificate thumbprints that are associated with an OpenID Connect (OIDC) provider resource
Grants permission to update the description or maximum session duration setting of a role
Grants permission to update only the description of a role
Grants permission to update the metadata document for an existing SAML provider resource
Grants permission to update the name or the path of the specified server certificate stored in IAM
Grants permission to update the status of a service-specific credential to active or inactive for an IAM user
Grants permission to update the status of the specified user signing certificate to active or disabled
Grants permission to update the status of an IAM user's SSH public key to active or inactive
Grants permission to update the name or the path of the specified IAM user
Grants permission to upload a CloudFront public key
Grants permission to upload a server certificate entity for the AWS account
Grants permission to upload an X.509 signing certificate and associate it with the specified IAM user
Grants permission to upload an SSH public key and associate it with the specified IAM user