Amazon managed policies for Amazon Resource Groups
An Amazon managed policy is a standalone policy that is created and administered by Amazon. Amazon managed policies are designed to provide permissions for many common use cases so that you can start assigning permissions to users, groups, and roles.
Keep in mind that Amazon managed policies might not grant least-privilege permissions for your specific use cases because they're available for all Amazon customers to use. We recommend that you reduce permissions further by defining customer managed policies that are specific to your use cases.
You cannot change the permissions defined in Amazon managed policies. If Amazon updates the permissions defined in an Amazon managed policy, the update affects all principal identities (users, groups, and roles) that the policy is attached to. Amazon is most likely to update an Amazon managed policy when a new Amazon Web Service is launched or new API operations become available for existing services.
For more information, see Amazon managed policies in the IAM User Guide.
Amazon-managed policies for Resource Groups
Amazon managed policy: ResourceGroupsServiceRolePolicy
You can't attach ResourceGroupsServiceRolePolicy
to any IAM entities yourself. This
policy can be attached only to a service-linked role that allows Resource Groups to perform
actions on your behalf. For more information, see Using service-linked roles for
Resource Groups.
This policy grants the permissions required for Resource Groups to retrieve information about the resources in your resource groups and any Amazon CloudFormation stacks that those resources belong to. This lets Resource Groups generate CloudWatch Events for the group lifecycle events feature.
To see the latest version of this Amazon managed policy, see ResourceGroupsServiceRolePolicy
in the IAM console.
Amazon managed policy: ResourceGroupsandTagEditorFullAccess
When you attach a policy to a principal entity, you give the entity permissions that are defined in the policy. Amazon managed policies make it easier for you to assign appropriate permissions to users, groups, and roles than if you had to write the policies yourself.
This policy grants the permissions required for full access to Resource Groups and Tag Editor functionality.
To see the latest version of this Amazon managed policy, see ResourceGroupsandTagEditorFullAccess
in the IAM console.
For more information about this policy, see ResourceGroupsandTagEditorFullAccessin the Amazon Managed Policy Reference Guide.
Amazon managed policy: ResourceGroupsandTagEditorReadOnlyAccess
When you attach a policy to a principal entity, you give the entity permissions that are defined in the policy. Amazon managed policies make it easier for you to assign appropriate permissions to users, groups, and roles than if you had to write the policies yourself.
This policy grants the permissions required for read only access to Resource Groups and Tag Editor functionality.
To see the latest version of this Amazon managed policy, see ResourceGroupsandTagEditorReadOnlyAccess
in the IAM console.
For more information about this policy, see ResourceGroupsandTagEditorReadOnlyAccessin the Amazon Managed Policy Reference Guide.
Resource Groups updates to Amazon managed policies
View details about updates to Amazon managed policies for Resource Groups since this service began tracking these changes. For automatic alerts about changes to this page, subscribe to the RSS feed on the Resource Groups Document history page.
Change | Description | Date |
---|---|---|
Policy update – ResourceGroupsandTagEditorFullAccess | Resource Groups updated a policy to include additional Amazon CloudFormation permissions. | August 10, 2023 |
Policy update – ResourceGroupsandTagEditorReadOnlyAccess | Resource Groups updated a policy to include additional Amazon CloudFormation permissions. | August 10, 2023 |
New policy – ResourceGroupsServiceRolePolicy | Resource Groups added a new policy to support its service-linked role. | November 17, 2022 |
Resource Groups started tracking changes |
Resource Groups started tracking changes for its Amazon managed policies. |
November 17, 2022 |