View a markdown version of this page

AWS services that work with IAM - AWS Identity and Access Management

AWS services that work with IAM

The AWS services listed below are grouped alphabetically and include information about what IAM features they support:

  • Service – You can choose the name of a service to view the AWS documentation about IAM authorization and access for that service.

  • Actions – You can specify individual actions in a policy. If the service does not support this feature, then All actions is selected in the visual editor. In a JSON policy document, you must use * in the Action element. For a list of actions in each service, see Actions, Resources, and Condition Keys for AWS Services.

  • Resource-level permissions – You can use ARNs to specify individual resources in the policy. If the service does not support this feature, then All resources is chosen in the policy visual editor. In a JSON policy document, you must use * in the Resource element. Some actions, such as List* actions, do not support specifying an ARN because they are designed to return multiple resources. If a service supports this feature for some resources but not others, it is indicated by Partial in the table. See the documentation for that service for more information.

  • Resource-based policies – You can attach resource-based policies to a resource within the service. Resource-based policies include a Principal element to specify which IAM identities can access that resource. For more information, see Identity-based policies and resource-based policies.

  • ABAC (authorization based on tags) – To control access based on tags, you provide tag information in the condition element of a policy using the aws:ResourceTag/key-name, aws:RequestTag/key-name, or aws:TagKeys condition keys. If a service supports all three condition keys for every resource type, then the value is Yes for the service. If a service supports all three condition keys for only some resource types, then the value is Partial.

    For more information about defining permissions based on attributes such as tags, see Define permissions based on attributes with ABAC authorization. To view a tutorial with steps for setting up ABAC, see Use attribute-based access control (ABAC).

  • Temporary credentials – You can use short-term credentials that you obtain when you sign in using IAM Identity Center, account access manager, switch roles in the console, or that you generate using AWS STS in the AWS CLI or AWS API. You can access services with a No value only while using your long-term IAM user credentials. This includes a user name and password or your user access keys. For more information, see Temporary security credentials in IAM.

  • Service-linked roles – A service-linked role is a special type of service role that gives the service permission to access resources in other services on your behalf. Choose the Yes or Partial link to see the documentation for services that support these roles. This column does not indicate if the service uses standard service roles. For more information, see Service-linked roles.

  • More information – If a service doesn't fully support a feature, you can review the footnotes for an entry to view the limitations and links to related information.

Services that work with IAM

Service Actions Resource-level permissions Resource-based policies ABAC Temporary credentials Service-linked roles
Account access manager Yes Yes No Yes Yes Yes
AWS Account Management Yes Yes No No Yes No
AWS Action Recommendations Yes No No No Yes No
AWS Activate Console Yes No No No Yes No
Amazon AI Operations Yes Yes No Yes Yes No
AWS Amplify Admin Yes Yes No No Yes No
AWS Amplify Yes Yes No Partial Yes No
AWS Amplify UI Builder Yes Yes No Yes Yes No
Apache Kafka APIs for Amazon MSK clusters Yes Yes No No Yes No
Amazon API Gateway Yes Yes Yes No Yes Yes
Amazon API Gateway Management Yes Yes No Yes Yes No
Amazon API Gateway Management V2 Yes Yes No Yes Yes No
AWS App Studio Yes No No No Yes No
AWS App2Container Yes No No No Yes No
AWS AppConfig Yes Yes No Yes Yes No
AWS AppFabric Yes Yes No Yes Yes No
Amazon AppFlow Yes Yes No Yes Yes No
Amazon AppIntegrations Yes Yes No Yes Yes Yes
Application Auto Scaling Yes Yes No Yes Yes Yes
AWS Application Discovery Arsenal Yes No No No Yes No
AWS Application Discovery Service Yes No No No Yes Yes
AWS Transform MGN Yes Yes No Yes Yes Yes
Amazon Application Recovery Controller - Zonal Shift Yes Yes No No Yes No
AWS Application Transformation Service Yes No No No Yes No

AWS App Mesh

Yes Yes No Yes Yes Yes

AWS App Mesh Preview

Yes Yes No No Yes Yes
AWS App Runner Yes Yes No Yes Yes Yes
Amazon AppStream 2.0 Yes Yes No Yes Yes No
AWS AppSync Yes Yes No Yes Yes No
Amazon ARC Region Switch Yes Yes No Yes Yes No
AWS Artifact Yes Yes No No Yes No
Amazon Athena Yes Yes No Yes Yes No
AWS Audit Manager Yes Yes No Yes Yes Yes
Amazon Aurora DSQL Yes Yes No Yes Yes Yes
AWS Auto Scaling Yes No No No Yes Yes
AWS B2B Data Interchange Yes Yes No Yes Yes No
AWS Backup Yes Yes Yes Yes Yes Yes
AWS Backup Gateway Yes Yes No Yes Yes No
AWS Backup Search Yes Yes No Yes Yes No
AWS Backup storage Yes No No No Yes No
AWS Batch Yes Partial No Yes Yes Yes
Amazon Bedrock Yes Yes No Yes Yes No
Amazon Bedrock Agentcore Yes Yes No Partial Yes No
AWS Billing and Cost Management Yes Yes No Yes Yes Yes
AWS Billing and Cost Management Dashboards Yes No No No Yes No
AWS Billing and Cost Management Data Exports Yes Yes No Yes Yes No
AWS Billing and Cost Management Pricing Calculator Yes Yes No Yes Yes No
AWS Billing and Cost Management Recommended Actions Yes No No No Yes No
AWS Billing Conductor Yes Yes No Yes Yes No
Amazon Braket Yes Yes No Yes Yes Yes
AWS Budget Service Yes Yes No Yes Yes No
AWS Certificate Manager (ACM) Yes Yes No Yes Yes Yes
Amazon Q Developer in chat applications Yes Yes No Yes Yes Yes
Amazon Chime Yes Yes No Yes Yes Yes
AWS Clean Rooms Yes Yes No Yes Yes No
AWS Clean Rooms ML Yes Yes No Yes Yes No
AWS Client VPN Yes Yes No No Yes Yes
AWS Cloud9 Yes Yes Yes Yes Yes Yes
AWS Cloud Control API Yes No No No Yes No
Amazon Cloud Directory Yes Yes No No Yes