Identity Type | Support |
---|---|
AWS IAM Role | ✅ |
AWS IAM User | ✅ |
AWS IAM Group | ✅ |
Policy Type | Support |
---|---|
Inline policy | ✅ |
Managed Policy (Custom / AWS Managed) | ✅ |
Permissions boundary | ✅ |
Resource based policy | ❌ |
Group Linked Policies | ❌ |
SCPs | ❌ |
VPC Endpoint policies | ❌ |
Type | Support |
---|---|
Properties of the principal | Partial |
Properties of the resource | Partial (aws:ResourceAccount, aws:ResourceTag/tag::key) |
Properties of a role session | ❌ |
Properties of the network | ❌ |
Properties of the request | ❌ |
s3:GetObject
, s3:WriteObject
etc aren’t supported