-
Permissions acm-pca:CreatePermission acm-pca:DeletePermission acm-pca:DeletePolicy acm-pca:PutPolicy
-
certificate-authority
:arn:${Partition}:acm-pca:${Region}:${Account}:certificate-authority/${CertificateAuthorityId}
apigateway:UpdateRestApiPolicy
- ARN:
arn:${Partition}:apigateway:${Region}::${ApiGatewayResourcePath}
backup:DeleteBackupVaultAccessPolicy backup:PutBackupVaultAccessPolicy
backupVault
:arn:${Partition}:backup:${Region}:${Account}:backup-vault:${BackupVaultName}
chime:DeleteVoiceConnectorTerminationCredentials chime:PutVoiceConnectorTerminationCredentials
cloudsearch:UpdateServiceAccessPolicies
codeartifact:DeleteDomainPermissionsPolicy codeartifact:DeleteRepositoryPermissionsPolicy
codebuild:DeleteResourcePolicy codebuild:DeleteSourceCredentials codebuild:ImportSourceCredentials codebuild:PutResourcePolicy
codeguru-profiler:PutPermission codeguru-profiler:RemovePermission
codestar:AssociateTeamMember codestar:CreateProject codestar:DeleteProject codestar:DisassociateTeamMember codestar:UpdateTeamMember
cognito-identity:CreateIdentityPool cognito-identity:DeleteIdentities cognito-identity:DeleteIdentityPool cognito-identity:GetId cognito-identity:MergeDeveloperIdentities cognito-identity:SetIdentityPoolRoles cognito-identity:UnlinkDeveloperIdentity cognito-identity:UnlinkIdentity cognito-identity:UpdateIdentityPool
deeplens:AssociateServiceRoleToAccount
ds:CreateConditionalForwarder ds:CreateDirectory ds:CreateMicrosoftAD ds:CreateTrust ds:ShareDirectory
ec2:CreateNetworkInterfacePermission ec2:DeleteNetworkInterfacePermission ec2:ModifyVpcEndpointServicePermissions
ec2:ModifySnapshotAttribute ec2:ResetSnapshotAttribute
- Repositories
ecr:DeleteRepositoryPolicy ecr:SetRepositoryPolicy ecr-public:SetRepositoryPolicy
elasticfilesystem:DeleteFileSystemPolicy elasticfilesystem:PutFileSystemPolicy
elasticmapreduce:PutBlockPublicAccessConfiguration
es:CreateElasticsearchDomain es:UpdateElasticsearchDomainConfig
glacier:AbortVaultLock glacier:CompleteVaultLock glacier:DeleteVaultAccessPolicy glacier:InitiateVaultLock glacier:SetDataRetrievalPolicy glacier:SetVaultAccessPolicy
glue:DeleteResourcePolicy glue:PutResourcePolicy
greengrass:AssociateServiceRoleToAccount
health:DisableHealthServiceAccessForOrganization health:EnableHealthServiceAccessForOrganization
iam:AttachRolePolicy
iam:CreatePolicy iam:CreatePolicyVersion iam:CreateRole iam:DeletePolicy iam:DeletePolicyVersion iam:DeleteRole iam:DeleteRolePermissionsBoundary iam:DeleteRolePolicy iam:DetachRolePolicy iam:PassRole iam:PutRolePermissionsBoundary iam:PutRolePolicy iam:UpdateAssumeRolePolicy iam:UpdateRole
imagebuilder:GetContainerRecipePolicy imagebuilder:PutComponentPolicy imagebuilder:PutContainerRecipePolicy imagebuilder:PutImagePolicy imagebuilder:PutImageRecipePolicy
iot:AttachPolicy iot:AttachPrincipalPolicy iot:DetachPolicy iot:DetachPrincipalPolicy iot:SetDefaultAuthorizer iot:SetDefaultPolicyVersion
iotsitewise:CreateAccessPolicy iotsitewise:DeleteAccessPolicy iotsitewise:UpdateAccessPolicy
kms:CreateGrant kms:PutKeyPolicy kms:RetireGrant kms:RevokeGrant
lakeformation:BatchGrantPermissions lakeformation:BatchRevokePermissions lakeformation:GrantPermissions lakeformation:PutDataLakeSettings lakeformation:RevokePermissions
lambda:AddLayerVersionPermission lambda:AddPermission lambda:DisableReplication lambda:EnableReplication lambda:RemoveLayerVersionPermission lambda:RemovePermission
logs:DeleteResourcePolicy logs:PutResourcePolicy
mediastore:DeleteContainerPolicy mediastore:PutContainerPolicy
opsworks:SetPermission opsworks:UpdateUserProfile
quicksight:CreateAdmin quicksight:CreateGroup quicksight:CreateGroupMembership quicksight:CreateIAMPolicyAssignment quicksight:CreateUser quicksight:DeleteGroup quicksight:DeleteGroupMembership quicksight:DeleteIAMPolicyAssignment quicksight:DeleteUser quicksight:DeleteUserByPrincipalId quicksight:DescribeDataSetPermissions quicksight:DescribeDataSourcePermissions quicksight:RegisterUser quicksight:UpdateDashboardPermissions quicksight:UpdateDataSetPermissions quicksight:UpdateDataSourcePermissions quicksight:UpdateGroup quicksight:UpdateIAMPolicyAssignment quicksight:UpdateTemplatePermissions quicksight:UpdateUser
ram:AcceptResourceShareInvitation ram:AssociateResourceShare ram:CreateResourceShare ram:DeleteResourceShare ram:DisassociateResourceShare ram:EnableSharingWithAwsOrganization ram:RejectResourceShareInvitation ram:UpdateResourceShare
redshift:AuthorizeSnapshotAccess redshift:CreateClusterUser redshift:CreateSnapshotCopyGrant redshift:JoinGroup redshift:ModifyClusterIamRoles redshift:RevokeSnapshotAccess
route53resolver:PutResolverRulePolicy
s3:BypassGovernanceRetention s3:DeleteAccessPointPolicy s3:DeleteBucketPolicy s3:ObjectOwnerOverrideToBucketOwner s3:PutAccessPointPolicy s3:PutAccountPublicAccessBlock s3:PutBucketAcl s3:PutBucketPolicy s3:PutBucketPublicAccessBlock s3:PutObjectAcl s3:PutObjectVersionAcl
s3-outposts:DeleteAccessPointPolicy s3-outposts:DeleteBucketPolicy s3-outposts:PutAccessPointPolicy s3-outposts:PutBucketPolicy s3-outposts:PutObjectAcl
secretsmanager:DeleteResourcePolicy secretsmanager:PutResourcePolicy secretsmanager:ValidateResourcePolicy
signer:AddProfilePermission signer:ListProfilePermissions signer:RemoveProfilePermission
sns:AddPermission sns:CreateTopic sns:RemovePermission sns:SetTopicAttributes
sqs:AddPermission sqs:CreateQueue sqs:RemovePermission sqs:SetQueueAttributes
ssm:ModifyDocumentPermission
sso:AssociateDirectory sso:AssociateProfile sso:CreateApplicationInstance sso:CreateApplicationInstanceCertificate sso:CreatePermissionSet sso:CreateProfile sso:CreateTrust sso:DeleteApplicationInstance sso:DeleteApplicationInstanceCertificate sso:DeletePermissionSet sso:DeletePermissionsPolicy sso:DeleteProfile sso:DisassociateDirectory sso:DisassociateProfile sso:ImportApplicationInstanceServiceProviderMetadata sso:PutPermissionsPolicy sso:StartSSO sso:UpdateApplicationInstanceActiveCertificate sso:UpdateApplicationInstanceDisplayData sso:UpdateApplicationInstanceResponseConfiguration sso:UpdateApplicationInstanceResponseSchemaConfiguration sso:UpdateApplicationInstanceSecurityConfiguration sso:UpdateApplicationInstanceServiceProviderConfiguration sso:UpdateApplicationInstanceStatus sso:UpdateDirectoryAssociation sso:UpdatePermissionSet sso:UpdateProfile sso:UpdateSSOConfiguration sso:UpdateTrust sso-directory:AddMemberToGroup sso-directory:CreateAlias sso-directory:CreateGroup sso-directory:CreateUser sso-directory:DeleteGroup sso-directory:DeleteUser sso-directory:DisableUser sso-directory:EnableUser sso-directory:RemoveMemberFromGroup sso-directory:UpdateGroup sso-directory:UpdatePassword sso-directory:UpdateUser sso-directory:VerifyEmail
storagegateway:DeleteChapCredentials storagegateway:SetLocalConsolePassword storagegateway:SetSMBGuestPassword storagegateway:UpdateChapCredentials
waf:DeletePermissionPolicy waf:PutPermissionPolicy waf-regional:DeletePermissionPolicy waf-regional:PutPermissionPolicy wafv2:CreateWebACL wafv2:DeletePermissionPolicy wafv2:DeleteWebACL wafv2:PutPermissionPolicy wafv2:UpdateWebACL