Amazon managed policies for Amazon Directory Service - Amazon Directory Service
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Amazon managed policies for Amazon Directory Service

An Amazon managed policy is a standalone policy that is created and administered by Amazon. Amazon managed policies are designed to provide permissions for many common use cases so that you can start assigning permissions to users, groups, and roles.

Keep in mind that Amazon managed policies might not grant least-privilege permissions for your specific use cases because they're available for all Amazon customers to use. We recommend that you reduce permissions further by defining customer managed policies that are specific to your use cases.

You cannot change the permissions defined in Amazon managed policies. If Amazon updates the permissions defined in an Amazon managed policy, the update affects all principal identities (users, groups, and roles) that the policy is attached to. Amazon is most likely to update an Amazon managed policy when a new Amazon Web Services service is launched or new API operations become available for existing services.

For more information, see Amazon managed policies in the IAM User Guide.

The following sections describe the Amazon managed policies that are specific to Amazon Directory Service. You can attach these policies to users in your account.

For more information, see Amazon managed policies in the IAM User Guide.

Amazon managed policy: AWSDirectoryServiceFullAccess

You can attach the AWSDirectoryServiceFullAccess policy to your IAM identities. To view the full permissions for this policy, see AWSDirectoryServiceFullAccess in the Amazon Managed Policy Reference.

This policy grants administrative permissions that allow a principal full access to all Amazon Directory Service actions. Principals with these permissions can create, configure, and manage directories, including Simple AD, AD Connector, and Managed Microsoft AD. They can also manage directory sharing, trust relationships, and monitoring configurations. This policy includes permissions to manage the underlying network infrastructure required for directory services.

Permissions details

This policy includes the following permissions:

  • ds – Allows principals full access to all Amazon Directory Service actions.

  • ec2 – Allows principals to manage network interfaces, security groups, and describe VPC resources required for directory operations.

  • sns – Allows principals to create and manage SNS topics for directory monitoring, specifically topics with names beginning with "DirectoryMonitoring".

  • iam – Allows principals to list IAM roles for directory service operations.

  • organizations – Allows principals to manage Amazon Organizations integration and enable/disable service access for directory services.

Amazon managed policy: AWSDirectoryServiceReadOnlyAccess

You can attach the AWSDirectoryServiceReadOnlyAccess policy to your IAM identities. To view the full permissions for this policy, see AWSDirectoryServiceReadOnlyAccess in the Amazon Managed Policy Reference.

This policy grants read-only permissions that allow users to view information in Amazon Directory Service. Principals with this policy attached cannot make any updates to directories or their configurations. For example, principals with these permissions can view directory details, trust relationships, and monitoring configurations, but cannot create new directories or modify existing ones. They can also view related EC2 network resources and SNS topics associated with directories.

Permissions details

This policy includes the following permissions:

  • ds – Allows users to perform read-only actions that return directory information. This includes API operations that start with Check, Describe, Get, List, or Verify.

  • ec2 – Allows users to describe network interfaces, subnets, and VPCs associated with directory services.

  • sns – Allows users to list and get information about SNS topics and subscriptions used for directory monitoring.

  • organizations – Allows users to describe Amazon Organizations accounts and service access configurations related to directory services.

Amazon managed policy: AWSDirectoryServiceDataFullAccess

You can attach the AWSDirectoryServiceDataFullAccess policy to your IAM identities. To view the full permissions for this policy, see AWSDirectoryServiceDataFullAccess in the Amazon Managed Policy Reference.

This policy grants administrative permissions that allow a principal full access to Directory Service Data operations. Principals with these permissions can create, update, and delete Active Directory users and groups within managed directories. They can manage group memberships, enable or disable users, and perform comprehensive user and group management operations. This policy is designed for administrators who need to manage Active Directory objects programmatically.

Permissions details

This policy includes the following permissions:

  • ds – Allows principals to access directory data through the Directory Service Data API.

  • ds-data – Allows principals full access to all Directory Service Data operations, including creating, updating, and deleting users and groups, managing group memberships, and searching directory objects.

Amazon managed policy: AWSDirectoryServiceDataReadOnlyAccess

You can attach the AWSDirectoryServiceDataReadOnlyAccess policy to your IAM identities. To view the full permissions for this policy, see AWSDirectoryServiceDataReadOnlyAccess in the Amazon Managed Policy Reference.

This policy grants read-only permissions that allow users to view and search Active Directory objects within managed directories. Principals with this policy attached cannot make any updates to users, groups, or group memberships. For example, principals with these permissions can search for users and groups, view user and group details, and list group memberships, but cannot create, modify, or delete any directory objects.

Permissions details

This policy includes the following permissions:

  • ds – Allows principals to access directory data through the Directory Service Data API.

  • ds-data – Allows users to perform read-only actions that return directory object information. This includes API operations that start with Describe, List, or Search.

AWSDirectoryServiceServiceRolePolicy

You cannot attach the AWSDirectoryServiceServiceRolePolicy policy to your IAM identities. This policy is attached to a service-linked role that allows Amazon Directory Service to perform actions on your behalf. To view the permissions for this policy, see AWSDirectoryServiceServiceRolePolicy in the Amazon Managed Policy Reference.

This policy grants permissions that allow Amazon Directory Service to monitor and assess self-managed domain controllers in hybrid Active Directory environments. The service uses these permissions to run automated health assessments, execute PowerShell scripts for compatibility testing, and gather network configuration information to ensure proper hybrid connectivity and automated recovery capabilities.

Permissions details

This policy includes the following permissions:

  • ssm – Allows the service to send PowerShell commands to on-premises domain controllers and retrieve command execution results for monitoring and assessment purposes.

  • ec2 – Allows the service to describe network resources such as VPCs, subnets, security groups, and network interfaces to validate hybrid connectivity configurations.

IAM and Amazon Directory Service updates to Amazon managed policies

View details about updates to IAM and Amazon managed policies since the service began tracking these changes. For automatic alerts about changes to this page, subscribe to the RSS feed on the IAM and Amazon Directory Service Document history pages.

Change Description Date

AWSDirectoryServiceServiceRolePolicy – New policy

Amazon Directory Service added a new policy to allow Amazon to monitor a customer's self-managed domain controllers.

July 30, 2025

Amazon managed policy: AWSDirectoryServiceDataReadOnlyAccess – New policy

Amazon Directory Service added a new policy to allow a user or group access to view and search AD users, members, and groups.

September 17, 2024

Amazon managed policy: AWSDirectoryServiceDataFullAccess – New policy

Amazon Directory Service added a new policy to allow a user or group access to built-in object management with Directory Service Data to create, manage, and view AD users, members, and groups.

September 17, 2024

Amazon Directory Service started tracking changes

Amazon Directory Service started tracking changes for its Amazon managed policies.

September 17, 2024