Amazon managed policies for Amazon Resource Explorer
An Amazon managed policy is a standalone policy that is created and administered by Amazon. Amazon managed policies are designed to provide permissions for many common use cases so that you can start assigning permissions to users, groups, and roles.
Keep in mind that Amazon managed policies might not grant least-privilege permissions for your specific use cases because they're available for all Amazon customers to use. We recommend that you reduce permissions further by defining customer managed policies that are specific to your use cases.
You cannot change the permissions defined in Amazon managed policies. If Amazon updates the permissions defined in an Amazon managed policy, the update affects all principal identities (users, groups, and roles) that the policy is attached to. Amazon is most likely to update an Amazon managed policy when a new Amazon Web Services service is launched or new API operations become available for existing services.
For more information, see Amazon managed policies in the IAM User Guide.
General Amazon managed policies that include Resource Explorer permissions
-
AdministratorAccess
– Grants full access to Amazon Web Services services and resources. -
ReadOnlyAccess
– Grants read-only access to Amazon Web Services services and resources. -
ViewOnlyAccess
– Grants permissions to view resources and basic metadata for Amazon Web Services services. Note
The Resource Explorer
Get*permissions included in theViewOnlyAccesspolicy perform likeListpermissions although they return only a single value, because a Region can contain only one index and one default view.
Amazon managed policies for Resource Explorer
Amazon managed policy: AWSResourceExplorerFullAccess
You can assign the AWSResourceExplorerFullAccess policy to your IAM
identities.
This policy grants permissions that allow full administrative control of the Resource Explorer service. You can perform all tasks involved in turning on and managing Resource Explorer in the Amazon Web Services Regions in your account. With this policy, the Resource Explorer console shows information from other integrated Amazon services and allows you to perform actions such as creating an application.
Permissions details
This policy includes permissions that allow all actions for Resource Explorer, including turning on and turning off Resource Explorer in Amazon Web Services Regions, creating or deleting an aggregator index for the account, creating, updating, and deleting views, and searching. This policy also includes permissions that are not part of Resource Explorer:
-
ec2:DescribeRegions– allows Resource Explorer to access the details about the Regions in your account. -
ram:ListResources– allows Resource Explorer to list the resource shares that resources are part of. -
ram:GetResourceShares– allows Resource Explorer to identify details about the resource shares that you own or that are shared with you. -
iam:CreateServiceLinkedRole(included in the AWSResourceExplorerFullAccess managed policy) – allows Resource Explorer to create the required service-linked role when you turn on Resource Explorer by creating the first index. -
organizations:DescribeOrganization– allows Resource Explorer to access information about your organization.
To see the latest version of this Amazon managed policy, see AWSResourceExplorerFullAccess in the Amazon Managed Policy
Reference Guide.
Amazon managed policy: AWSResourceExplorerReadOnlyAccess
You can assign the AWSResourceExplorerReadOnlyAccess policy to your IAM
identities.
This policy grants read-only permissions that allows users to discover their resources with basic search access, and access other integrated Amazon services in the Resource Explorer console.
Permissions details
This policy includes permissions that allow users to perform the Resource Explorer
Get*, List*, and Search operations to view
information about Resource Explorer components and configuration settings, but doesn't allow users
to change them. Users can also search. This policy also includes two permissions that
are not part of Resource Explorer:
-
ec2:DescribeRegions– allows Resource Explorer to access the details about the Regions in your account. -
ram:ListResources– allows Resource Explorer to list the resource shares that resources are part of. -
ram:GetResourceShares– allows Resource Explorer to identify details about the resource shares that you own or that are shared with you. -
organizations:DescribeOrganization– allows Resource Explorer to access information about your organization.
To see the latest version of this Amazon managed policy, see AWSResourceExplorerReadOnlyAccess in the Amazon Managed Policy
Reference Guide.
Amazon managed policy: AWSResourceExplorerServiceRolePolicy
You can't attach AWSResourceExplorerServiceRolePolicy to any IAM entities yourself.
This policy can be attached only to a service-linked role that allows Resource Explorer to perform
actions on your behalf. For more information, see Using service-linked roles for Resource Explorer.
This policy grants the permissions required for Resource Explorer to retrieve information about your resources. Resource Explorer populates the indexes it maintains in each Amazon Web Services Region that you register.
To see the latest version of this Amazon managed policy, AWSResourceExplorerServiceRolePolicy in the Amazon Managed Policy
Reference Guide.
Amazon managed policy: AWSResourceExplorerOrganizationsAccess
You can assign AWSResourceExplorerOrganizationsAccess to your IAM identities.
This policy grants administrative permissions to Resource Explorer and grants read-only permissions to other Amazon Web Services services to support this access. The Amazon Organizations administrator needs these permissions to set up and manage multi-account search in the console.
Permissions details
This policy includes permissions that allow administrators to set up multi-account search for the organization:
-
ec2:DescribeRegions– Allows Resource Explorer to access the details about the Regions in your account. -
ram:ListResources– Allows Resource Explorer to list the resource shares that resources are part of. -
ram:GetResourceShares– Allows Resource Explorer to identify details about the resource shares that you own or that are shared with you. -
organizations:ListAccounts– Allows Resource Explorer to identify the accounts within an organization. -
organizations:ListRoots– Allows Resource Explorer to identify the root accounts within an organization. -
organizations:ListOrganizationalUnitsForParent– Allows Resource Explorer to identify the organizational units (OUs) in a parent organizational unit or root. -
organizations:ListAccountsForParent– Allows Resource Explorer to identify the accounts in an organization that are contained by the specified target root or an OU. -
organizations:ListDelegatedAdministrators– Allows Resource Explorer to identify the Amazon accounts that are designated as delegated administrators in this organization. -
organizations:ListAWSServiceAccessForOrganization– Allows Resource Explorer to identify a list of the Amazon Web Services services that are enabled to integrate with your organization. -
organizations:DescribeOrganization– Allows Resource Explorer to retrieve information about the organization that the user's account belongs to. -
organizations:EnableAWSServiceAccess– Allows Resource Explorer to enable the integration of an Amazon Web Services service (the service that is specified byServicePrincipal) with Amazon Organizations. -
organizations:DisableAWSServiceAccess– Allows Resource Explorer to disable the integration of an Amazon Web Services service (the service that is specified by ServicePrincipal) with Amazon Organizations. -
organizations:RegisterDelegatedAdministrator– Allows Resource Explorer to enable the specified member account to administer the organization's features of the specified Amazon service. -
organizations:DeregisterDelegatedAdministrator– Allows Resource Explorer to remove the specified member Amazon Web Services account as a delegated administrator for the specified Amazon Web Services service. -
iam:GetRole– Allows Resource Explorer to retrieve information about the specified role, including the role's path, GUID, ARN, and the role's trust policy that grants permission to assume the role. -
iam:CreateServiceLinkedRole(included in the AWSResourceExplorerFullAccess managed policy) – Allows Resource Explorer to create the required service-linked role when you turn on Resource Explorer by creating the first index.
To see the latest version of this Amazon managed policy, see AWSResourceExplorerOrganizationsAccess in the Amazon Managed Policy
Reference Guide.
Resource Explorer updates to Amazon managed policies
View details about updates to Amazon managed policies for Resource Explorer since this service began tracking these changes. For automatic alerts about changes to this page, subscribe to the RSS feed on the Resource Explorer Document history page.
| Change | Description | Date |
|---|---|---|
|
AWSResourceExplorerServiceRolePolicy - Updated policy permissions to view additional resource types |
Resource Explorer modified the permissions in the service-linked role policy AWSResourceExplorerServiceRolePolicy. Permissions were added that allows Resource Explorer to view additional resource types:
|
August 15, 2026 |
|
AWSResourceExplorerServiceRolePolicy - Updated policy permissions to view additional resource types |
Resource Explorer modified the permissions in the service-linked role policy AWSResourceExplorerServiceRolePolicy. Permissions were added that allows Resource Explorer to view additional resource types:
|
June 23, 2026 |
|
AWSResourceExplorerServiceRolePolicy - Updated policy permissions to view additional resource types |
Resource Explorer modified the permissions in the service-linked role policy AWSResourceExplorerServiceRolePolicy. Permissions were added that allows Resource Explorer to view additional resource types:
|
February 04, 2026 |
|
AWSResourceExplorerServiceRolePolicy - Updated policy permissions to view additional resource types |
Resource Explorer modified the permissions in the service-linked role policy AWSResourceExplorerServiceRolePolicy. Permissions were added that allows Resource Explorer to view additional resource types:
|
December 16, 2025 |
|
AWSResourceExplorerServiceRolePolicy - Updated policy permissions to view additional resource types |
Resource Explorer modified the permissions in the service-linked role policy AWSResourceExplorerServiceRolePolicy. Permissions were added that allows Resource Explorer to view additional resource types:
|
November 17, 2025 |
|
AWSResourceExplorerServiceRolePolicy - Updated policy permissions to view additional resource types |
Resource Explorer modified the permissions in the service-linked role policy AWSResourceExplorerServiceRolePolicy. Permissions were added that allows Resource Explorer to view additional resource types:
|
October 13, 2025 |
|
AWSResourceExplorerServiceRolePolicy - Updated policy permissions to view additional resource types |
Resource Explorer modified the permissions in the service-linked role policy AWSResourceExplorerServiceRolePolicy. Permissions were added that allows Resource Explorer to view additional resource types:
|
September 24, 2025 |
|
AWSResourceExplorerServiceRolePolicy - Updated policy permissions to view additional resource types |
Resource Explorer modified the permissions in the service-linked role policy AWSResourceExplorerServiceRolePolicy. Permissions were added that allows Resource Explorer to view additional resource types:
|
September 15, 2025 |
|
AWSResourceExplorerServiceRolePolicy - Updated policy permissions for Amazon policy best practices |
Resource Explorer modified the permissions in the service-linked role policy
AWSResourceExplorerServiceRolePolicy.
Permissions were removed for resource types that are not currently
supported by Resource Explorer. For the latest version of this policy, see
The following permissions were removed for unsupported resource types:
|
September 5, 2025 |
|
AWSResourceExplorerServiceRolePolicy - Updated policy permissions to view additional resource types |
Resource Explorer modified the permissions in the service-linked role policy AWSResourceExplorerServiceRolePolicy. Permissions were added that allows Resource Explorer to view additional resource types:
|
August 4, 2025 |
|
AWSResourceExplorerServiceRolePolicy - Updated policy permissions to allow Resource Explorer to manage indexes and views |
Resource Explorer modified the permissions in the service-linked role policy AWSResourceExplorerServiceRolePolicy. The following permissions were added that allow Resource Explorer to create, manage, and delete indexes and views:
|
July 23, 2025 |
|
AWSResourceExplorerServiceRolePolicy - Updated policy permissions to view additional resource types |
Resource Explorer modified the permissions in the service-linked role policy AWSResourceExplorerServiceRolePolicy. Permissions were added that allows Resource Explorer to view additional resource types:
|
May 7, 2025 |
|
AWSResourceExplorerServiceRolePolicy - Updated policy permissions to view additional resource types |
Resource Explorer added permissions to the service-linked role policy AWSResourceExplorerServiceRolePolicy that allows Resource Explorer to view additional resource types:
|
March 21, 2025 |
|
AWSResourceExplorerServiceRolePolicy - Updated policy permissions to view additional resource types |
Resource Explorer added permissions to the service-linked role policy AWSResourceExplorerServiceRolePolicy that allows Resource Explorer to view additional resource types:
|
January 6, 2025 |
|
AWSResourceExplorerServiceRolePolicy - Updated policy permissions to view additional resource types |
Resource Explorer added permissions to the service-linked role policy AWSResourceExplorerServiceRolePolicy that allows Resource Explorer to view additional resource types:
|
November 21, 2024 |
|
AWSResourceExplorerServiceRolePolicy - Updated policy permissions to view additional resource types |
Resource Explorer added permissions to the service-linked role policy AWSResourceExplorerServiceRolePolicy that allows Resource Explorer to view additional resource types:
|
December 12, 2023 |
|
New managed policy |
Resource Explorer added the following Amazon managed policy: |
November 14, 2023 |
|
Updated managed policies |
Resource Explorer updated the following Amazon managed policies to support multi-account search: |
November 14, 2023 |
|
AWSResourceExplorerServiceRolePolicy – Updated policy to support multi-account search with Organizations |
Resource Explorer added permissions to the service-linked role policy
|
November 14, 2023 |
|
AWSResourceExplorerServiceRolePolicy – Updated policy to support additional resource types |
Resource Explorer added permissions to the service-linked role policy
|
October 17, 2023 |
|
AWSResourceExplorerServiceRolePolicy – Updated policy to support additional resource types |
Resource Explorer added permissions to the service-linked role policy
|
August 1, 2023 |
|
AWSResourceExplorerServiceRolePolicy – Updated policy to support additional resource types |
Resource Explorer added permissions to the service-linked role policy
|
March 7, 2023 |
| New managed policies |
Resource Explorer added the following Amazon managed policies: |
November 7, 2022 |
|
Resource Explorer started tracking changes |
Resource Explorer started tracking changes for its Amazon managed policies. |
November 7, 2022 |