Amazon managed policies for Amazon Systems Manager - Amazon Systems Manager
AmazonSSMServiceRolePolicyAmazonSSMAutomationRoleAmazonSSMReadOnlyAccessAWSSystemsManagerOpsDataSyncServiceRolePolicyAmazonSSMManagedEC2InstanceDefaultPolicySSMQuickSetupRolePolicyAWSQuickSetupDeploymentRolePolicyAWSQuickSetupPatchPolicyDeploymentRolePolicyAWSQuickSetupPatchPolicyBaselineAccessAWSSystemsManagerEnableExplorerExecutionPolicyAWSSystemsManagerEnableConfigRecordingExecutionPolicyAWSQuickSetupDevOpsGuruPermissionsBoundaryAWSQuickSetupDistributorPermissionsBoundaryAWSQuickSetupSSMHostMgmtPermissionsBoundaryAWSQuickSetupPatchPolicyPermissionsBoundaryAWSQuickSetupSchedulerPermissionsBoundaryAWSQuickSetupCFGCPacksPermissionsBoundaryAWSQuickSetupStartStopInstancesExecutionPolicyAWSQuickSetupStartSSMAssociationsExecutionPolicyAWS-SSM-DiagnosisAutomation-AdministrationRolePolicyAWS-SSM-DiagnosisAutomation-ExecutionRolePolicyAWS-SSM-RemediationAutomation-AdministrationRolePolicyAWS-SSM-RemediationAutomation-ExecutionRolePolicyAWSQuickSetupSSMManageResourcesExecutionPolicyAWSQuickSetupSSMLifecycleManagementExecutionPolicyAWSQuickSetupSSMDeploymentRolePolicyAWSQuickSetupSSMDeploymentS3BucketRolePolicyAWSQuickSetupEnableDHMCExecutionPolicyAWSQuickSetupEnableAREXExecutionPolicyAWSQuickSetupManagedInstanceProfileExecutionPolicyAWSQuickSetupManageJITNAResourcesExecutionPolicyAWSQuickSetupJITNADeploymentRolePolicyAWSSystemsManagerJustInTimeAccessServicePolicyAWSSystemsManagerJustInTimeAccessTokenPolicyAWSSystemsManagerJustInTimeAccessTokenSessionPolicyAWSSystemsManagerJustInTimeNodeAccessRolePropagationPolicyAWSSystemsManagerNotificationsServicePolicyAWS-SSM-Automation-DiagnosisBucketPolicyAWS-SSM-RemediationAutomation-OperationalAccountAdministrationRolePolicyAWS-SSM-DiagnosisAutomation-OperationalAccountAdministrationRolePolicyPolicy updatesAdditional managed policies for Systems Manager
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Amazon managed policies for Amazon Systems Manager

An Amazon managed policy is a standalone policy that is created and administered by Amazon. Amazon managed policies are designed to provide permissions for many common use cases so that you can start assigning permissions to users, groups, and roles.

Keep in mind that Amazon managed policies might not grant least-privilege permissions for your specific use cases because they're available for all Amazon customers to use. We recommend that you reduce permissions further by defining customer managed policies that are specific to your use cases.

You cannot change the permissions defined in Amazon managed policies. If Amazon updates the permissions defined in an Amazon managed policy, the update affects all principal identities (users, groups, and roles) that the policy is attached to. Amazon is most likely to update an Amazon managed policy when a new Amazon Web Services service is launched or new API operations become available for existing services.

For more information, see Amazon managed policies in the IAM User Guide.

Topics

Amazon managed policy: AmazonSSMServiceRolePolicy

This policy provides access to a number of Amazon resources that are managed by Amazon Systems Manager or used in Systems Manager operations.

You can't attach AmazonSSMServiceRolePolicy to your Amazon Identity and Access Management (IAM) entities. This policy is attached to a service-linked role that allows Amazon Systems Manager to perform actions on your behalf. For more information, see Using roles to collect inventory and view OpsData.

Permissions details

This policy includes the following permissions.

  • ssm – Allows principals to start and step executions for both Run Command and Automation; and to retrieve information about Run Command and Automation operations; to retrieve information about Parameter Store parameters Change Calendar calendars; to update and retrieve information about Systems Manager service settings for OpsCenterresources; and to read information about tags that have have applied to resources.

  • cloudformation – Allows principals to retrieve information about stackset operations and stackset instances, and to delete stacksets on the resource arn:aws-cn:cloudformation:*:*:stackset/AWS-QuickSetup-SSM*:*. Allows principals to delete stack instances that are associated with the following resources:

    arn:aws-cn:cloudformation:*:*:stackset/AWS-QuickSetup-SSM*:*
    arn:aws-cn:cloudformation:*:*:stackset-target/AWS-QuickSetup-SSM*:*
    arn:aws-cn:cloudformation:*:*:type/resource/*
  • cloudwatch – Allows principals to retrieve information about Amazon CloudWatch alarms.

  • compute-optimizer – Allows principals to retrieve the enrollment (opt in) status of an account to the Amazon Compute Optimizer service, and to retrieve recommendations for Amazon EC2 instances that meet a specific set of stated requirements.

  • config – Allows principals to retrieve information remediation configurations and configuration recorders in Amazon Config, and to determine whether specified Amazon Config rules and Amazon resources are compliant.

  • events – Allows principals retrieve information about EventBridge rules; to create EventBridge rules and targets exclusively for the the Systems Manager service (ssm.amazonaws.com.cn); and to delete rules and targets for the resource arn:aws-cn:events:*:*:rule/SSMExplorerManagedRule.

  • ec2 – Allows principals to retrieve information about Amazon EC2 instances..

  • iam – Allows principals to pass roles permissions for the Systems Manager service (ssm.amazonaws.com.cn).

  • lambda – Allows principals to invoke Lambda functions that are configured specifically for use by Systems Manager.

  • resource-explorer-2 – Allows principals to retrieve data about EC2 instances to determine whether or not each instance is currently managed by Systems Manager.

    The action resource-explorer-2:CreateManagedView is allowed for the arn:aws:resource-explorer-2:*:*:managed-view/AWSManagedViewForSSM* resource.

  • resource-groups – Allows principals to retrieve list resource groups and their members from Amazon Resource Groups of resources that belong to a resource group.

  • securityhub – Allows principals to retrieve information about Amazon Security Hub hub resources in the current account.

  • states – Allows principals to start and retrieve information for Amazon Step Functions that are configured specifically for use by Systems Manager.

  • support – Allows principals to retrieve information about checks and cases in Amazon Trusted Advisor.

  • tag – Allows principals to retrieve information about all the tagged or previously tagged resources that are located in a specified Amazon Web Services Region for an account.

To view more details about the policy, including the latest version of the JSON policy document, see AmazonSSMServiceRolePolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AmazonSSMAutomationRole

You can attach the AmazonSSMAutomationRole policy to your IAM identities. This policy provides permissions for the Amazon Systems Manager Automation service to run activities defined within Automation runbooks.

Permissions details

This policy includes the following permissions.

  • lambda – Allows principals to invoke Lambda functions with names that begin with "Automation". This is required for Automation runbooks to execute Lambda functions as part of their workflow.

  • ec2 – Allows principals to perform various Amazon EC2 operations including creating, copying, and deregistering images; managing snapshots; starting, running, stopping, and terminating instances; managing instance status; and creating, deleting, and describing tags. These permissions enable Automation runbooks to manage Amazon EC2 resources during execution.

  • cloudformation – Allows principals to create, describe, update, and delete Amazon CloudFormation stacks. This enables Automation runbooks to manage infrastructure as code through CloudFormation.

  • ssm – Allows principals to use all Systems Manager actions. This comprehensive access is required for Automation runbooks to interact with all Systems Manager capabilities.

  • sns – Allows principals to publish messages to Amazon SNS topics with names that begin with "Automation". This enables Automation runbooks to send notifications during execution.

  • ssmmessages – Allows principals to open data channels to Systems Manager sessions. This enables Automation runbooks to establish communication channels for session-based operations.

To view more details about the policy, including the latest version of the JSON policy document, see AmazonSSMAutomationRole in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AmazonSSMReadOnlyAccess

You can attach the AmazonSSMReadOnlyAccess policy to your IAM identities. This policy grants read-only access to Amazon Systems Manager API operations including Describe*, Get*, and List*.

To view more details about the policy, including the latest version of the JSON policy document, see AmazonSSMReadOnlyAccess in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSSystemsManagerOpsDataSyncServiceRolePolicy

You can't attach AWSSystemsManagerOpsDataSyncServiceRolePolicy to your IAM entities. This policy is attached to a service-linked role that allows Systems Manager to perform actions on your behalf. For more information, see Using roles to create OpsData and OpsItems for Explorer.

AWSSystemsManagerOpsDataSyncServiceRolePolicy allows the AWSServiceRoleForSystemsManagerOpsDataSync service-linked role to create and update OpsItems and OpsData from Amazon Security Hub findings.

The policy allows Systems Manager to complete the following actions on all related resources ("Resource": "*"), except where indicated:

  • ssm:GetOpsItem [1]

  • ssm:UpdateOpsItem [1]

  • ssm:CreateOpsItem

  • ssm:AddTagsToResource [2]

  • ssm:UpdateServiceSetting [3]

  • ssm:GetServiceSetting [3]

  • securityhub:GetFindings

  • securityhub:GetFindings

  • securityhub:BatchUpdateFindings [4]

[1] The ssm:GetOpsItem and ssm:UpdateOpsItem actions are allowed permissions by the following condition for the Systems Manager service only.

"Condition": { "StringEquals": { "aws:ResourceTag/ExplorerSecurityHubOpsItem": "true" } }

[2] The ssm:AddTagsToResource action is allowed permissions for the following resource only.

arn:aws-cn:ssm:*:*:opsitem/*

[3] The ssm:UpdateServiceSetting and ssm:GetServiceSetting actions are allowed permissions for the following resources only.

arn:aws-cn:ssm:*:*:servicesetting/ssm/opsitem/* arn:aws-cn:ssm:*:*:servicesetting/ssm/opsdata/*

[4] The securityhub:BatchUpdateFindings are denied permissions by the following condition for the Systems Manager service only.

{ "Effect": "Deny", "Action": "securityhub:BatchUpdateFindings", "Resource": "*", "Condition": { "StringEquals": { "securityhub:ASFFSyntaxPath/Workflow.Status": "SUPPRESSED" } } }, { "Effect": "Deny", "Action": "securityhub:BatchUpdateFindings", "Resource": "*", "Condition": { "Null": { "securityhub:ASFFSyntaxPath/Confidence": false } } }, { "Effect": "Deny", "Action": "securityhub:BatchUpdateFindings", "Resource": "*", "Condition": { "Null": { "securityhub:ASFFSyntaxPath/Criticality": false } } }, { "Effect": "Deny", "Action": "securityhub:BatchUpdateFindings", "Resource": "*", "Condition": { "Null": { "securityhub:ASFFSyntaxPath/Note.Text": false } } }, { "Effect": "Deny", "Action": "securityhub:BatchUpdateFindings", "Resource": "*", "Condition": { "Null": { "securityhub:ASFFSyntaxPath/Note.UpdatedBy": false } } }, { "Effect": "Deny", "Action": "securityhub:BatchUpdateFindings", "Resource": "*", "Condition": { "Null": { "securityhub:ASFFSyntaxPath/RelatedFindings": false } } }, { "Effect": "Deny", "Action": "securityhub:BatchUpdateFindings", "Resource": "*", "Condition": { "Null": { "securityhub:ASFFSyntaxPath/Types": false } } }, { "Effect": "Deny", "Action": "securityhub:BatchUpdateFindings", "Resource": "*", "Condition": { "Null": { "securityhub:ASFFSyntaxPath/UserDefinedFields.key": false } } }, { "Effect": "Deny", "Action": "securityhub:BatchUpdateFindings", "Resource": "*", "Condition": { "Null": { "securityhub:ASFFSyntaxPath/UserDefinedFields.value": false } } }, { "Effect": "Deny", "Action": "securityhub:BatchUpdateFindings", "Resource": "*", "Condition": { "Null": { "securityhub:ASFFSyntaxPath/VerificationState": false } }

To view more details about the policy, including the latest version of the JSON policy document, see AWSSystemsManagerOpsDataSyncServiceRolePolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AmazonSSMManagedEC2InstanceDefaultPolicy

You should only attach AmazonSSMManagedEC2InstanceDefaultPolicy to IAM roles for Amazon EC2 instances that you want to have permission to use Systems Manager functionality. You shouldn't attached this role to other IAM entities, such as IAM users and IAM groups, or to IAM roles that serve other purposes. For more information, see Managing EC2 instances automatically with Default Host Management Configuration.

This policy grants permissions that allow SSM Agent on your Amazon EC2 instance to communicate with the Systems Manager service in the cloud in order to perform a variety of tasks. It also grants permissions for the two services that provide authorization tokens to ensure that operations are performed on the correct instance.

Permissions details

This policy includes the following permissions.

  • ssm – Allows principals to retrieve Documents, execute commands using Run Command, establish sessions using Session Manager, collect an inventory of the instance, and scan for patches and patch compliance using Patch Manager.

  • ssmmessages – Allows principals to access, for each instance, a personalized authorization token that was created by the Amazon Message Gateway Service. Systems Manager validates the personalized authorization token against the Amazon Resource Name (ARN) of the instance that was provided in the API operation. This access is necessary to ensure that SSM Agent performs the API operations on the correct instance.

  • ec2messages – Allows principals to access, for each instance, a personalized authorization token that was created by the Amazon Message Delivery Service. Systems Manager validates the personalized authorization token against the Amazon Resource Name (ARN) of the instance that was provided in the API operation. This access is necessary to ensure that SSM Agent performs the API operations on the correct instance.

For related information about the ssmmessages and ec2messages endpoints, including the differences between the two, see Agent-related API operations (ssmmessages and ec2messages endpoints).

To view more details about the policy, including the latest version of the JSON policy document, see AmazonSSMManagedEC2InstanceDefaultPolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: SSMQuickSetupRolePolicy

You can't attach SSMQuickSetupRolePolicy to your IAM entities. This policy is attached to a service-linked role that allows Systems Manager to perform actions on your behalf. For more information, see Using roles to maintain Quick Setup-provisioned resource health and consistency.

This policy grants read-only permissions that allow Systems Manager to check configuration health, ensure consistent use of parameters and provisioned resources, and remediate resources when drift is detected. It also grants administrative permissions for creating a service-linked role.

Permissions details

This policy includes the following permissions.

  • ssm – Allows principals to read information Resource Data Syncs and SSM Documents in Systems Manager, including in delegated administrator accounts. This is required so Quick Setup can determine the state that configured resources are intended to be in.

  • organizations – Allows principals to read information about the member accounts that belong to an organization as configured in Amazon Organizations. This is required so Quick Setup can identify all accounts in an organization where resource health checks are to be performed.

  • cloudformation – Allows principals to read information from Amazon CloudFormation. This is required so Quick Setup can gather data about the Amazon CloudFormation stacks used to manage the state of resources and CloudFormation stackset operations.

To view more details about the policy, including the latest version of the JSON policy document, see SSMQuickSetupRolePolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSQuickSetupDeploymentRolePolicy

The managed policy AWSQuickSetupDeploymentRolePolicy supports multiple Quick Setup configuration types. These configuration types create IAM roles and automations that configure frequently used Amazon Web Services services and features with recommended best practices.

You can attach AWSQuickSetupDeploymentRolePolicy to your IAM entities.

This policy grants administrative permissions needed to create resources associated with the following Quick Setup configurations:

Permissions details

This policy includes the following permissions.

  • ssm – Allows principals to read, create, update, and delete SSM documents with names beginning with "AWSQuickSetup-" or "AWSOperationsPack-" when called via Amazon CloudFormation; to read specific Amazon owned documents including "AWSQuickSetupType-ManageInstanceProfile"; to create, update, and delete associations for Quick Setup documents and Amazon owned documents when called via Amazon CloudFormation; and to clean up legacy resources tagged with QuickSetupID. This enables Quick Setup to deploy and manage automation workflows and associations.

  • cloudformation – Allows principals to read information about Amazon CloudFormation stacks and stack sets; and to create, update, and delete Amazon CloudFormation stacks and change sets for resources with names beginning with "StackSet-AWS-QuickSetup-". This enables Quick Setup to manage infrastructure deployments across accounts and regions.

  • config – Allows principals to read information about Amazon Config conformance packs and their status; and to create and delete conformance packs with names beginning with "AWS-QuickSetup-" when called via Amazon CloudFormation. This enables Quick Setup to deploy compliance monitoring configurations.

  • events – Allows principals to manage EventBridge rules and targets for resources with names containing "QuickSetup-". This enables Quick Setup to create scheduled automation workflows.

  • iam – Allows principals to create service-linked roles for Amazon Config and Systems Manager; to create, manage, and delete IAM roles with names beginning with "AWS-QuickSetup-" or "AWSOperationsPack-" when called via Amazon CloudFormation; to pass these roles to Systems Manager and EventBridge services; to attach specific Amazon managed policies to these roles; and to set permissions boundaries using specific Quick Setup managed policies. This enables Quick Setup to create the necessary service roles for its operations.

  • resource-groups – Allows principals to retrieve resource group queries. This enables Quick Setup to target specific sets of resources for configuration management.

To view more details about the policy, including the latest version of the JSON policy document, see AWSQuickSetupDeploymentRolePolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSQuickSetupPatchPolicyDeploymentRolePolicy

The managed policy AWSQuickSetupPatchPolicyDeploymentRolePolicy supports the Configure patching for instances in an organization using a Quick Setup patch policy Quick Setup type. This configuration type helps automate patching of applications and nodes in a single account or across your organization.

You can attach AWSQuickSetupPatchPolicyDeploymentRolePolicy to your IAM entities. Systems Manager also attaches this policy to a service role that allows Systems Manager to perform actions on your behalf.

This policy grants administrative permissions that allow Quick Setup to create resources associated with a patch policy configuration.

Permissions details

This policy includes the following permissions.

  • iam – Allows principals to manage and delete IAM roles required for Automation configuration tasks; and to manage Automation role policies.

  • cloudformation – Allows principals to read Amazon CloudFormation stack information; and to control Amazon CloudFormation stacks that were created by Quick Setup using Amazon CloudFormation stack sets.

  • ssm – Allows principals to create, update, read, and delete Automation runbooks required for configuration tasks; and to create, update, and delete State Manager associations.

  • resource-groups – Allows principals to retrieve resource queries that are associated with resource groups targeted by Quick Setup configurations.

  • s3 – Allows principals to list Amazon S3 buckets; and to manage the buckets for storing patch policy access logs.

  • lambda – Allows principals to manage Amazon Lambda remediation functions that maintain configurations in the correct state.

  • logs – Allows principals to describe and manage log groups for Lambda configuration resources.

To view more details about the policy, including the latest version of the JSON policy document, see AWSQuickSetupPatchPolicyDeploymentRolePolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSQuickSetupPatchPolicyBaselineAccess

The managed policy AWSQuickSetupPatchPolicyBaselineAccess supports the Configure patching for instances in an organization using a Quick Setup patch policy Quick Setup type. This configuration type helps automate patching of applications and nodes in a single account or across your organization.

You can attach AWSQuickSetupPatchPolicyBaselineAccess to your IAM entities. Systems Manager also attaches this policy to a service role that allows Systems Manager to perform actions on your behalf.

This policy provides read-only permissions to access patch baselines that have been configured by an administrator in the current Amazon Web Services account or organization using Quick Setup. The patch baselines are stored in an Amazon S3 bucket and can be used for patching instances in a single account or across an entire organization.

Permissions details

This policy includes the following permission.

  • s3 – Allows principals to read patch baseline overrides stored in Amazon S3 buckets.

To view more details about the policy, including the latest version of the JSON policy document, see AWSQuickSetupPatchPolicyBaselineAccess in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSSystemsManagerEnableExplorerExecutionPolicy

The managed policy AWSSystemsManagerEnableExplorerExecutionPolicy supports enabling Explorer, a tool in Amazon Systems Manager.

You can attach AWSSystemsManagerEnableExplorerExecutionPolicy to your IAM entities. Systems Manager also attaches this policy to a service role that allows Systems Manager to perform actions on your behalf.

This policy grants administrative permissions for enabling Explorer. This includes permissions to update related Systems Manager service settings, and to create a service-linked role for Systems Manager.

Permissions details

This policy includes the following permissions.

  • config – Allows principals to help enable Explorer by providing read-only access to configuration recorder details.

  • iam – Allows principals to help enable Explorer.

  • ssm – Allows principals to start an Automation workflow that enables Explorer.

To view more details about the policy, including the latest version of the JSON policy document, see AWSSystemsManagerEnableExplorerExecutionPolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSSystemsManagerEnableConfigRecordingExecutionPolicy

The managed policy AWSSystemsManagerEnableConfigRecordingExecutionPolicy supports the Create an Amazon Config configuration recorder using Quick Setup Quick Setup configuration type. This configuration type enables Quick Setup to track and record changes to the Amazon resource types you choose for Amazon Config. It also enables Quick Setup to configure delivery and notifications options for the recorded data.

You can attach AWSSystemsManagerEnableConfigRecordingExecutionPolicy to your IAM entities. Systems Manager also attaches this policy to a service role that allows Systems Manager to perform actions on your behalf.

This policy grants administrative permissions that allow Quick Setup to enable and configure Amazon Config configuration recording.

Permissions details

This policy includes the following permissions.

  • s3 – Allows principals to create and configure Amazon S3 buckets for delivery of configuration recordings.

  • sns – Allows principals to list and create Amazon SNS topics.

  • config – Allows principals to configure and start the configuration recorder; and to help enable Explorer.

  • iam – Allows principals to create, get, and pass a service-linked role for Amazon Config; and to create a service-linked role for Systems Manager; and to help enable Explorer.

  • ssm – Allows principals to start an Automation workflow that enables Explorer.

  • compute-optimizer – Allows principals to help enable Explorer by providing read-only access to determine whether a resource is enrolled with Amazon Compute Optimizer.

  • support – Allows principals to help enable Explorer by providing read-only access to determine whether a resource is enrolled with Amazon Compute Optimizer.

To view more details about the policy, including the latest version of the JSON policy document, see AWSSystemsManagerEnableConfigRecordingExecutionPolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSQuickSetupDevOpsGuruPermissionsBoundary

Note

This policy is a permissions boundary. A permissions boundary sets the maximum permissions that an identity-based policy can grant to an IAM entity. You should not use and attach Quick Setup permissions boundary policies on your own. Quick Setup permissions boundary policies should only be attached to Quick Setup managed roles. For more information about permissions boundaries, see Permissions boundaries for IAM entities in the IAM User Guide.

The managed policy AWSQuickSetupDevOpsGuruPermissionsBoundary supports the Set up DevOps Guru using Quick Setup type. The configuration type enables the machine learning-powered Amazon DevOps Guru. The DevOps Guru service can help improve an application’s operational performance and availability.

When you create an AWSQuickSetupDevOpsGuruPermissionsBoundary configuration using Quick Setup, the system applies this permissions boundary to the IAM roles that are created when the configuration is deployed. The permissions boundary limits the scope of the roles that Quick Setup creates.

This policy grants administrative permissions that allow Quick Setup to enable and configure Amazon DevOps Guru.

Permissions details

This policy includes the following permissions.

  • iam – Allows principals to create service-linked roles for DevOps Guru and Systems Manager; and to list roles that help enable Explorer.

  • cloudformation – Allows principals to list and describe Amazon CloudFormation stacks.

  • sns – Allows principals to list and create Amazon SNS topics.

  • devops-guru – Allows principals to configure DevOps Guru; and to add a notification channel.

  • config – – Allows principals to help enable Explorer by providing read-only access to configuration recorder details.

  • ssm – Allows principals to start an Automation workflow that enables Explorer; and to read and update Explorer service settings.

  • compute-optimizer – Allows principals to help enable Explorer by providing read-only access to determine whether a resource is enrolled with Amazon Compute Optimizer.

  • support – Allows principals to help enable Explorer by providing read-only access to determine whether a resource is enrolled with Amazon Compute Optimizer.

To view more details about the policy, including the latest version of the JSON policy document, see AWSQuickSetupDevOpsGuruPermissionsBoundary in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSQuickSetupDistributorPermissionsBoundary

Note

This policy is a permissions boundary. A permissions boundary sets the maximum permissions that an identity-based policy can grant to an IAM entity. You should not use and attach Quick Setup permissions boundary policies on your own. Quick Setup permissions boundary policies should only be attached to Quick Setup managed roles. For more information about permissions boundaries, see Permissions boundaries for IAM entities in the IAM User Guide.

The managed policy AWSQuickSetupDistributorPermissionsBoundary supports the Deploy Distributor packages using Quick Setup Quick Setup configuration type. The configuration type helps enable the distribution of software packages, such as agents, to your Amazon Elastic Compute Cloud (Amazon EC2) instances, using Distributor, a tool in Amazon Systems Manager.

When you create an AWSQuickSetupDistributorPermissionsBoundary configuration using Quick Setup, the system applies this permissions boundary to the IAM roles that are created when the configuration is deployed. The permissions boundary limits the scope of the roles that Quick Setup creates.

This policy grants administrative permissions that allow Quick Setup to enable the distribution of software packages, such as agents, to your Amazon EC2 instances using Distributor.

Permissions details

This policy includes the following permissions.

  • iam – Allows principals to get and pass the Distributor automation role; to create, read, update, and delete the default instance role; to pass the default instance role to Amazon EC2 and Systems Manager; to attach instance management policies to instance roles; to create a service-linked role for Systems Manager; to add the default instance role to instance profiles; to read information about IAM roles and instance profiles; and to create the default instance profile.

  • ec2 – Allows principals to associate the default instance profile with EC2 instances; and to help enable Explorer.

  • ssm – Allows principals to start automation workflows that which configure instances and install packages; and to help start the automation workflow that enables Explorer; and to read and update Explorer service settings.

  • config – Allows principals to help enable Explorer by providing read-only access to configuration recorder details.

  • compute-optimizer – Allows principals to help enable Explorer by providing read-only access to determine whether a resource is enrolled with Amazon Compute Optimizer.

  • support – Allows principals to help enable Explorer by providing read-only access to determine whether a resource is enrolled with Amazon Compute Optimizer.

To view more details about the policy, including the latest version of the JSON policy document, see AWSQuickSetupDistributorPermissionsBoundary in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSQuickSetupSSMHostMgmtPermissionsBoundary

Note

This policy is a permissions boundary. A permissions boundary sets the maximum permissions that an identity-based policy can grant to an IAM entity. You should not use and attach Quick Setup permissions boundary policies on your own. Quick Setup permissions boundary policies should only be attached to Quick Setup managed roles. For more information about permissions boundaries, see Permissions boundaries for IAM entities in the IAM User Guide.

The managed policy AWSQuickSetupSSMHostMgmtPermissionsBoundary supports the Set up Amazon EC2 host management using Quick Setup Quick Setup configuration type. This configuration type configures IAM roles and enables commonly used Systems Manager tools to securely manage your Amazon EC2 instances.

When you create an AWSQuickSetupSSMHostMgmtPermissionsBoundary configuration using Quick Setup, the system applies this permissions boundary to the IAM roles that are created when the configuration is deployed. The permissions boundary limits the scope of the roles that Quick Setup creates.

This policy grants administrative permissions that allow Quick Setup to enable and configure Systems Manager tools needed for securely managing EC2 instances.

Permissions details

This policy includes the following permissions.

  • iam – Allows principals to get and pass the service role to Automation. Allows principals to create, read, update, and delete the default instance role; to pass the default instance role to Amazon EC2 and Systems Manager; to attach instance management policies to instance roles; to create a service-linked role for Systems Manager; to add the default instance role to instance profiles; to read information about IAM roles and instance profiles; and to create the default instance profile.

  • ec2 – Allows principals to associate and disassociate the default instance profile with EC2 instances.

  • ssm – Allows principals to start Automation workflows that enable Explorer; to read and update Explorer service settings; to configure instances; and to enable Systems Manager tools on instances.

  • compute-optimizer – Allows principals to help enable Explorer by providing read-only access to determine whether a resource is enrolled with Amazon Compute Optimizer.

  • support – Allows principals to help enable Explorer by providing read-only access to determine whether a resource is enrolled with Amazon Compute Optimizer.

To view more details about the policy, including the latest version of the JSON policy document, see AWSQuickSetupSSMHostMgmtPermissionsBoundary in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSQuickSetupPatchPolicyPermissionsBoundary

Note

This policy is a permissions boundary. A permissions boundary sets the maximum permissions that an identity-based policy can grant to an IAM entity. You should not use and attach Quick Setup permissions boundary policies on your own. Quick Setup permissions boundary policies should only be attached to Quick Setup managed roles. For more information about permissions boundaries, see Permissions boundaries for IAM entities in the IAM User Guide.

The managed policy AWSQuickSetupPatchPolicyPermissionsBoundary supports the Configure patching for instances in an organization using a Quick Setup patch policy Quick Setup type. This configuration type helps automate patching of applications and nodes in a single account or across your organization.

When you create an AWSQuickSetupPatchPolicyPermissionsBoundary configuration using Quick Setup, the system applies this permissions boundary to the IAM roles that are created when the configuration is deployed. The permissions boundary limits the scope of the roles that Quick Setup creates.

This policy grants administrative permissions that allow Quick Setup to enable and configure patch policies in Patch Manager, a tool in Amazon Systems Manager.

Permissions details

This policy includes the following permissions.

  • iam – Allows principals to get the Patch Manager Automation role; to pass Automation roles to Patch Manager patching operations; to create the default instance role, AmazonSSMRoleForInstancesQuickSetup; to pass the default instance role to Amazon EC2 and Systems Manager; to attach selected Amazon managed policies to the instance role; to create a service-linked role for Systems Manager; to add the default instance role to instance profiles; to read information about instance profiles and roles; to create a default instance profile; and to tag roles that have permissions to read patch baseline overrides.

  • ssm – Allows principals to update the instance role this is managed by Systems Manager; to manage associations created by Patch Manager patch policies created in Quick Setup; to tag instances targeted by a patch policy configuration; to read information about instances and patching status; to start Automation workflows that configure, enable and remediate instance patching; to start automation workflows that enable Explorer; to help enable Explorer; and to read and update Explorer service settings.

  • ec2 – Allows principals to associate and disassociate the default instance profile with EC2 instances; to tag instances targeted by a patch policy configuration; to tag instances targeted by a patch policy configuration; and to help enable Explorer.

  • s3 – Allows principals to create and configure S3 buckets to store patch baseline overrides.

  • lambda – Allows principals to invoke Amazon Lambda functions that configure patching and to perform clean-up operations after a Quick Setup patch policy configuration is deleted.

  • logs – Allows principals to configure logging for Patch Manager Quick Setup Amazon Lambda functions.

  • config – Allows principals to help enable Explorer by providing read-only access to configuration recorder details.

  • compute-optimizer – Allows principals to help enable Explorer by providing read-only access to determine whether a resource is enrolled with Amazon Compute Optimizer.

  • support – Allows principals to help enable Explorer by providing read-only access to determine whether a resource is enrolled with Amazon Compute Optimizer.

To view more details about the policy, including the latest version of the JSON policy document, see AWSQuickSetupPatchPolicyPermissionsBoundary in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSQuickSetupSchedulerPermissionsBoundary

Note

This policy is a permissions boundary. A permissions boundary sets the maximum permissions that an identity-based policy can grant to an IAM entity. You should not use and attach Quick Setup permissions boundary policies on your own. Quick Setup permissions boundary policies should only be attached to Quick Setup managed roles. For more information about permissions boundaries, see Permissions boundaries for IAM entities in the IAM User Guide.

The managed policy AWSQuickSetupSchedulerPermissionsBoundary supports the Stop and start EC2 instances automatically on a schedule using Quick Setup Quick Setup configuration type. This configuration type lets you stop and start your EC2 instances and other resources at the times you specify.

When you create an AWSQuickSetupSchedulerPermissionsBoundary configuration using Quick Setup, the system applies this permissions boundary to the IAM roles that are created when the configuration is deployed. The permissions boundary limits the scope of the roles that Quick Setup creates.

This policy grants administrative permissions that allow Quick Setup to enable and configure scheduled operations on EC2 instances and other resources.

Permissions details

This policy includes the following permissions.

  • iam – Allows principals to retrieve and pass roles for instance management automation actions; to manage, pass, and attach default instance roles for EC2 instance management; to create default instance profiles; to add default instance roles to instance profiles; to create a service-linked role for Systems Manager; to read information about IAM roles and instance profiles; to associate a default instance profile with EC2 instances; and to start Automation workflows to configure instances and enable Systems Manager tools on them.

  • ssm – Allows principals to start Automation workflows that enable Explorer; and to read and update Explorer service settings.

  • ec2 – Allows principals to locate targeted instances and to start and stop them on a schedule.

  • config – Allows principals to help enable Explorer by providing read-only access to configuration recorder details.

  • compute-optimizer – Allows principals to help enable Explorer by providing read-only access to determine whether a resource is enrolled with Amazon Compute Optimizer.

  • support – Allows principals to help enable Explorer by providing read-only access to Amazon Trusted Advisor checks for an account.

To view more details about the policy, including the latest version of the JSON policy document, see AWSQuickSetupSchedulerPermissionsBoundary in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSQuickSetupCFGCPacksPermissionsBoundary

Note

This policy is a permissions boundary. A permissions boundary sets the maximum permissions that an identity-based policy can grant to an IAM entity. You should not use and attach Quick Setup permissions boundary policies on your own. Quick Setup permissions boundary policies should only be attached to Quick Setup managed roles. For more information about permissions boundaries, see Permissions boundaries for IAM entities in the IAM User Guide.

The managed policy AWSQuickSetupCFGCPacksPermissionsBoundarysupports the Deploy Amazon Config conformance pack using Quick Setup Quick Setup configuration type. This configuration type deploys Amazon Config conformance packs. Conformance packs are collections of Amazon Config rules and remediation actions that can be deployed as a single entity.

When you create an AWSQuickSetupCFGCPacksPermissionsBoundary configuration using Quick Setup, the system applies this permissions boundary to the IAM roles that are created when the configuration is deployed. The permissions boundary limits the scope of the roles that Quick Setup creates.

This policy grants administrative permissions that allow Quick Setup to deploy Amazon Config conformance packs.

Permissions details

This policy includes the following permissions.

  • iam – Allows principals to create, get, and pass a service-linked role for Amazon Config.

  • sns – Allows principals to list platform applications in Amazon SNS.

  • config – Allows principals to deploy Amazon Config conformance packs; to get the status of conformance packs; and to get information about configuration recorders.

  • ssm – Allows principals to get information about SSM documents and Automation workflows; to get information about resource tags; and to get information about and update service settings.

  • compute-optimizer – Allows principals to get the opt-in status of an account.

  • support – Allows principals to get information about Amazon Trusted Advisor checks.

To view more details about the policy, including the latest version of the JSON policy document, see AWSQuickSetupCFGCPacksPermissionsBoundary in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSQuickSetupStartStopInstancesExecutionPolicy

You can attach AWSQuickSetupStartStopInstancesExecutionPolicy to your IAM entities. This policy provides permissions for Quick Setup to manage the starting and stopping of Amazon EC2 instances using Systems Manager automation.

Permissions details

This policy includes the following permissions.

  • ec2 – Allows principals to describe Amazon EC2 instances, their status, regions, and tags. Also allows starting and stopping specific Amazon EC2 instances.

  • ssm – Allows principals to get calendar state from Quick Setup change calendars, start associations, and execute automation documents for instance scheduling.

  • iam – Allows principals to pass Quick Setup IAM roles to Systems Manager for automation execution, with conditions that restrict the service to ssm.amazonaws.com and specific resource ARNs.

To view more details about the policy, including the latest version of the JSON policy document, see AWSQuickSetupStartStopInstancesExecutionPolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSQuickSetupStartSSMAssociationsExecutionPolicy

This policy grants permissions that allow Quick Setup to run the AWSQuickSetupType-Scheduler-ChangeCalendarState Automation runbook. This runbook is used to manage change calendar states for scheduled operations in Quick Setup configurations.

You can attach AWSQuickSetupStartSSMAssociationsExecutionPolicy to your IAM entities. Systems Manager also attaches this policy to a service role that allows Systems Manager to perform actions on your behalf.

Permissions details

This policy includes the following permissions.

  • ssm – Allows principals to start automation executions specifically for the AWSQuickSetupType-Scheduler-ChangeCalendarState document. This is required for Quick Setup to manage change calendar states for scheduled operations.

  • iam – Allows principals to pass roles with names that begin with "AWS-QuickSetup-" to the Systems Manager service. This permission is restricted to use with specific SSM documents related to change calendar management. This is required for Quick Setup to pass the appropriate execution role to the automation process.

To view more details about the policy, including the latest version of the JSON policy document, see AWSQuickSetupStartSSMAssociationsExecutionPolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWS-SSM-DiagnosisAutomation-AdministrationRolePolicy

The policy AWS-SSM-DiagnosisAutomation-AdministrationRolePolicy provides permissions for diagnosing issues with nodes that interact with Systems Manager services by starting Automation workflows in accounts and Regions where nodes are managed.

You can attach AWS-SSM-DiagnosisAutomation-AdministrationRolePolicy to your IAM entities. Systems Manager also attaches this policy to a service role that allows Systems Manager to perform diagnosis actions on your behalf.

Permissions details

This policy includes the following permissions.

  • ssm – Allows principals to run specific Automation runbooks that diagnose node issues, access the execution status for workflows, and retrieve automation execution details. The policy grants permissions to describe automation executions, describe automation step executions, get automation execution details, and start automation executions for diagnosis-related documents.

  • kms – Allows principals to use customer-specified Amazon Key Management Service keys for decryption and data key generation when accessing encrypted objects in Amazon S3 buckets used for diagnosis operations. These permissions are restricted to keys tagged with SystemsManagerManaged and used via Amazon S3 service with specific encryption context requirements.

  • sts – Allows principals to assume diagnosis execution roles to run Automation runbooks in the same account. This permission is restricted to roles with the AWS-SSM-DiagnosisExecutionRole naming pattern and includes a condition to ensure the resource account matches the principal account.

  • iam – Allows principals to pass the diagnosis administration role to Systems Manager to run Automation runbooks. This permission is restricted to roles with the AWS-SSM-DiagnosisAdminRole naming pattern and can only be passed to the Systems Manager service.

  • s3 – Allows principals to access, read, write, and delete objects in Amazon S3 buckets used for diagnosis operations. These permissions are restricted to buckets with the do-not-delete-ssm-diagnosis- naming pattern and include conditions to ensure operations are performed within the same account.

To view more details about the policy, including the latest version of the JSON policy document, see AWS-SSM-DiagnosisAutomation-AdministrationRolePolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWS-SSM-DiagnosisAutomation-ExecutionRolePolicy

The managed policy AWS-SSM-DiagnosisAutomation-ExecutionRolePolicy provides administrative permission for running Automation runbooks in a targeted Amazon Web Services account and Region to diagnose issues with managed nodes that interact with Systems Manager services.

You can attach AWS-SSM-DiagnosisAutomation-ExecutionRolePolicy to your IAM entities. Systems Manager also attaches this policy to a service role that allows Systems Manager to perform actions on your behalf.

Permissions details

This policy includes the following permissions.

  • ec2 – Allows principals to describe Amazon EC2 and Amazon VPC resources and their configurations to diagnose issues with Systems Manager services. This includes permissions to describe VPCs, VPC attributes, VPC endpoints, subnets, security groups, instances, and internet gateways.

  • ssm – Allows principals to run diagnosis-specific Automation runbooks and access the automation workflow status and execution metadata. This includes permissions to describe automation step executions, describe instance information, describe automation executions, get automation execution details, and start automation executions for specific Amazon unmanaged EC2 diagnosis documents.

  • kms – Allows principals to use customer-specified Amazon Key Management Service keys for decryption and data key generation when accessing encrypted objects in Amazon S3 buckets used for diagnosis operations. These permissions are restricted to keys tagged with SystemsManagerManaged and used via Amazon S3 service with specific encryption context requirements for diagnosis buckets.

  • iam – Allows principals to pass the diagnosis execution role to Systems Manager to run Automation documents. This permission is restricted to roles with the AWS-SSM-DiagnosisExecutionRole naming pattern and can only be passed to the Systems Manager service.

To view more details about the policy, including the latest version of the JSON policy document, see AWS-SSM-DiagnosisAutomation-ExecutionRolePolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWS-SSM-RemediationAutomation-AdministrationRolePolicy

The policy AWS-SSM-RemediationAutomation-AdministrationRolePolicy provides permissions for remediating issues with Systems Manager services by executing activities defined within Automation documents, primarily used for running the Automation documents. This policy enables starting Automation workflows in accounts and Regions where nodes are managed to address connectivity and configuration issues.

You can attach AWS-SSM-RemediationAutomation-AdministrationRolePolicy to your IAM entities. Systems Manager also attaches this policy to a service role that allows Systems Manager to perform remediation actions on your behalf.

Permissions details

This policy includes the following permissions.

  • ssm – Allows principals to run specific Automation runbooks that remediate node issues, access the execution status for workflows, and retrieve automation execution details. The policy grants permissions to describe automation executions, describe automation step executions, get automation execution details, and start automation executions for remediation-related documents.

  • kms – Allows principals to use customer-specified Amazon Key Management Service keys for decryption and data key generation when accessing encrypted objects in Amazon S3 buckets used for remediation operations. These permissions are restricted to keys tagged with SystemsManagerManaged and used via Amazon S3 service with specific encryption context requirements.

  • sts – Allows principals to assume remediation execution roles to run Automation runbooks in the same account. This permission is restricted to roles with the AWS-SSM-RemediationExecutionRole naming pattern and includes a condition to ensure the resource account matches the principal account.

  • iam – Allows principals to pass the remediation administration role to Systems Manager to run Automation runbooks. This permission is restricted to roles with the AWS-SSM-RemediationAdminRole naming pattern and can only be passed to the Systems Manager service.

  • s3 – Allows principals to access, read, write, and delete objects in Amazon S3 buckets used for remediation operations. These permissions are restricted to buckets with the do-not-delete-ssm-diagnosis- naming pattern and include conditions to ensure operations are performed within the same account.

To view more details about the policy, including the latest version of the JSON policy document, see AWS-SSM-RemediationAutomation-AdministrationRolePolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWS-SSM-RemediationAutomation-ExecutionRolePolicy

The managed policy AWS-SSM-RemediationAutomation-ExecutionRolePolicy provides permissions for running Automation runbooks in a specific target account and Region to remediate networking and connectivity issues with managed nodes that interact with Systems Manager services. This policy enables remediation activities defined within Automation documents, primarily used for running the Automation documents to address connectivity and configuration issues.

You can attach the policy to your IAM entities. Systems Manager also attaches this policy to a service role that allows Systems Manager to perform remediation actions on your behalf.

Permissions details

This policy includes the following permissions.

  • ssm – Allows principals to retrieve information about Automation executions and their step executions, and to start specific remediation Automation runbooks including AWS-OrchestrateUnmanagedEC2Actions and AWS-RemediateSSMAgent documents. The policy grants permissions to describe automation executions, describe automation step executions, get automation execution details, and start automation executions for remediation-related documents.

  • ec2 – Allows principals to describe and modify Amazon VPC networking resources to remediate connectivity issues. This includes:

    • Describing Amazon VPC attributes, subnets, Amazon VPC endpoints, and security groups.

    • Creating Amazon VPC endpoints for Systems Manager services (ssm, ssmmessages, and ec2messages) with required tags.

    • Modifying Amazon VPC attributes to enable DNS support and hostnames.

    • Creating and managing security groups with specific tags for Amazon VPC endpoint access.

    • Authorizing and revoking security group rules for HTTPS access with appropriate tags.

    • Creating tags on Amazon VPC endpoints, security groups, and security group rules during resource creation.

  • kms – Allows principals to use customer-specified Amazon Key Management Service keys for decryption and data key generation when accessing encrypted objects in Amazon S3 buckets used for remediation operations. These permissions are restricted to keys tagged with SystemsManagerManaged and used via Amazon S3 service with specific encryption context requirements.

  • iam – Allows principals to pass the remediation execution role to Systems Manager to run Automation runbooks. This permission is restricted to roles with the AWS-SSM-RemediationExecutionRole naming pattern and can only be passed to the Systems Manager service.

To view more details about the policy, including the latest version of the JSON policy document, see AWS-SSM-RemediationAutomation-ExecutionRolePolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSQuickSetupSSMManageResourcesExecutionPolicy

This policy grants permissions that allow Quick Setup to run the AWSQuickSetupType-SSM-SetupResources Automation runbook. This runbook creates IAM roles for Quick Setup associations, which in turn are created by a AWSQuickSetupType-SSM deployment. It also grants permissions to clean up an associated Amazon S3 bucket on during a Quick Setup delete operation.

You can attach the policy to your IAM entities. Systems Manager also attaches this policy to a service role that allows Systems Manager to perform actions on your behalf.

Permissions details

This policy includes the following permissions.

  • iam – Allows principals to list and manage IAM roles for use with Quick Setup Systems Manager Explorer operations; to view, attach, and detach IAM policies for use with Quick Setup and Systems Manager Explorer These permissions are required so Quick Setup can create the roles needed for some of its configuration operations.

  • s3 – Allows principals to retrieve information about objects in, and to delete objects from Amazon S3 buckets, in the principal account, that are used specifically in Quick Setup configuration operations. This is required so that S3 objects that are no longer needed after configuration can be removed.

To view more details about the policy, including the latest version of the JSON policy document, see AWSQuickSetupSSMManageResourcesExecutionPolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSQuickSetupSSMLifecycleManagementExecutionPolicy

The AWSQuickSetupSSMLifecycleManagementExecutionPolicy policy grants administrative permissions that allow Quick Setup to run the a Amazon CloudFormation custom resource on lifecycle events during Quick Setup deployment in Systems Manager.

You can attach this policy to your IAM entities. Systems Manager also attaches this policy to a service role that allows Systems Manager to perform actions on your behalf.

Permissions details

This policy includes the following permissions.

  • ssm – Allows principals to get information about automation executions and start automation executions for setting up certain Quick Setup operations.

  • iam – Allows principals to pass roles from IAM for setting up certain Quick Setup resources.

To view more details about the policy, including the latest version of the JSON policy document, see AWSQuickSetupSSMLifecycleManagementExecutionPolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSQuickSetupSSMDeploymentRolePolicy

The managed policy AWSQuickSetupSSMDeploymentRolePolicy grants administrative permissions that allow Quick Setup to create resources that are used during the Systems Manager onboarding process.

Though you can manually attach this policy to your IAM entities, this is not recommended. Quick Setup creates entities that attach this policy to a service role that allows Systems Manager to perform actions on your behalf.

This policy is not related to the SSMQuickSetupRolePolicy policy, which is used to provide permissions for the AWSServiceRoleForSSMQuickSetup service-linked role.

Permissions details

This policy includes the following permissions.

  • ssm – Allows principals to manage associations for certain resources that are created using Amazon CloudFormation templates and a specific set of SSM documents; to manage roles and role policies using for diagnosing and remediating managed nodes through Amazon CloudFormation templates; and to attach and delete policies for Quick Setup lifecycle events

  • iam – Allows principals to tag roles and pass roles permissions for the Systems Manager service and Lambda service, and to pass role permissions for diagnosis operations.

  • lambda – Allows principals to tag and manage functions for the Quick Setup lifecycle in the principal account using Amazon CloudFormation templates.

  • cloudformation – Allows principals to read information from Amazon CloudFormation. This is required so Quick Setup can gather data about the Amazon CloudFormation stacks used to manage the state of resources and CloudFormation stackset operations.

To view more details about the policy, including the latest version of the JSON policy document, see AWSQuickSetupSSMDeploymentRolePolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSQuickSetupSSMDeploymentS3BucketRolePolicy

The AWSQuickSetupSSMDeploymentS3BucketRolePolicy policy grants permissions for listing all S3 buckets in an account; and for managing and retrieving information about specific buckets in the principal account that are managed through Amazon CloudFormation templates.

You can attach AWSQuickSetupSSMDeploymentS3BucketRolePolicy to your IAM entities. Systems Manager also attaches this policy to a service role that allows Systems Manager to perform actions on your behalf.

Permissions details

This policy includes the following permissions.

  • s3 – Allows principals list all S3 buckets in an account; and to manage and retrieve information about specific buckets in the principal account that are managed through Amazon CloudFormation templates.

To view more details about the policy, including the latest version of the JSON policy document, see AWSQuickSetupSSMDeploymentS3BucketRolePolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSQuickSetupEnableDHMCExecutionPolicy

This policy grants administrative permissions that allow principals to run the AWSQuickSetupType-EnableDHMC Automation runbook, which enables Default Host Management Configuration. The Default Host Management Configuration setting allows Systems Manager to automatically manage Amazon EC2 instances as managed instances. A managed instance is an EC2 instance that is configured for use with Systems Manager. This policy also grants permissions for creating IAM roles that are specified in Systems Manager service settings as the default roles for SSM Agent.

You can attach AWSQuickSetupEnableDHMCExecutionPolicy to your IAM entities. Systems Manager also attaches this policy to a service role that allows Systems Manager to perform actions on your behalf.

Permissions details

This policy includes the following permissions.

  • ssm – Allows principals to update and get information about Systems Manager service settings.

  • iam – Allows principals to create and retrieve information about IAM roles for Quick Setup operations.

To view more details about the policy, including the latest version of the JSON policy document, see AWSQuickSetupEnableDHMCExecutionPolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSQuickSetupEnableAREXExecutionPolicy

This policy grants administrative permissions that allow Systems Manager to run the AWSQuickSetupType-EnableAREX Automation runbook, which enables Amazon Resource Explorer for use with Systems Manager. Resource Explorer makes it possible to view resources in your account with a search experience similar to an Internet search engine. The policy also grants permissions for managing Resource Explorer indexes and views.

You can attach AWSQuickSetupEnableAREXExecutionPolicy to your IAM entities. Systems Manager also attaches this policy to a service role that allows Systems Manager to perform actions on your behalf.

Permissions details

This policy includes the following permissions.

  • iam – Allows principals to to create a service-linked role in the Amazon Identity and Access Management (IAM) service.

  • resource-explorer-2 – Allows principals to retrieve information about Resource Explorer views and indexes; to create Resource Explorer views and indexes; to change the index type for indexes displayed in Quick Setup.

To view more details about the policy, including the latest version of the JSON policy document, see AWSQuickSetupEnableAREXExecutionPolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSQuickSetupManagedInstanceProfileExecutionPolicy

This policy grants administrative permissions that allow Systems Manager to create a default IAM instance profile for the Quick Setup tool, and to attach it to Amazon EC2 instances that don't already have an instance profile attached. The policy also grants Systems Manager the ability to attach permissions to existing instance profiles. This is done to ensure that the permissions required for Systems Manager to communicate with SSM Agent on EC2 instances are in place.

You can attach AWSQuickSetupManagedInstanceProfileExecutionPolicy to your IAM entities. Systems Manager also attaches this policy to a service role that allows Systems Manager to perform actions on your behalf.

Permissions details

This policy includes the following permissions.

  • ssm – Allows principals to start automation workflows associated with Quick Setup processes.

  • ec2 – Allows principals to attach IAM instance profiles to EC2 instances that are managed by Quick Setup.

  • iam – Allows principals to create, update, and retrieve information about roles from IAM that are used in Quick Setup processes; to create IAM instance profiles; to attach the AmazonSSMManagedInstanceCore managed policy to IAM instance profiles.

To view more details about the policy, including the latest version of the JSON policy document, see AWSQuickSetupManagedInstanceProfileExecutionPolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSQuickSetupManageJITNAResourcesExecutionPolicy

The managed policy AWSQuickSetupManageJITNAResourcesExecutionPolicy enables Quick Setup, a tool in Systems Manager, to set up just-in-time node access.

You can attach AWSQuickSetupManageJITNAResourcesExecutionPolicy to your IAM entities. Systems Manager also attaches this policy to a service role that allows Systems Manager to perform actions on your behalf.

This policy grants administrative permissions that allow Systems Manager to create resources associated with just-in-time node access.

Permissions details

This policy includes the following permissions.

  • ssm – Allows principals to get and update the service setting that specifies the identity provider for just-in-time node access.

  • iam – Allows principals to create, tag, and get roles, attach role policies for just-in-time node access managed policies, and create service-linked roles for just-in-time node access and notifications.

To view more details about the policy, including the latest version of the JSON policy document, see AWSQuickSetupManageJITNAResourcesExecutionPolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSQuickSetupJITNADeploymentRolePolicy

The managed policy AWSQuickSetupJITNADeploymentRolePolicy allows Quick Setup to deploy the configuration type required to set up just-in-time node access.

You can attach AWSQuickSetupJITNADeploymentRolePolicy to your IAM entities. Systems Manager also attaches this policy to a service role that allows Systems Manager to perform actions on your behalf.

This policy grants administrative permissions that allow Systems Manager to create resources associated with just-in-time node access.

Permissions details

This policy includes the following permissions.

  • cloudformation – Allows principals to create, update, delete, and read Amazon CloudFormation stacks.

  • ssm – Allows principals to create, delete, update, and read State Manager associations that are called by Amazon CloudFormation.

  • iam – Allows principals create, delete, read and tag IAM roles that are called by Amazon CloudFormation.

To view more details about the policy, including the latest version of the JSON policy document, see AWSQuickSetupJITNADeploymentRolePolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSSystemsManagerJustInTimeAccessServicePolicy

The managed policy AWSSystemsManagerJustInTimeAccessServicePolicy provides access to Amazon resources managed or used by the Amazon Systems Manager just-in-time access framework. This policy update adds automation execution tagging permissions to enable customers to scope down operator permissions to specific tags.

You can't attach AWSSystemsManagerJustInTimeAccessServicePolicy to your IAM entities. This policy is attached to a service-linked role that allows Systems Manager to perform actions on your behalf. For more information, see Using roles to enable just-in-time node access.

This policy grants administrative permissions that allows access to resources associated with just-in-time node access.

Permissions details

This policy includes the following permissions.

  • ssm – Allows principals to create and manage OpsItems, add tags to OpsItems and automation executions, get and update OpsItems, retrieve and describe documents, describe OpsItems and sessions, list documents and tags for managed instances.

  • ssm-guiconnect – Allows principals to list connections.

  • identitystore – Allows principals to get user and group IDs, describe users, and list group membership.

  • sso-directory – Allows principals to describe users and determine if a user is a member of a group.

  • sso – Allows principals to describe registered Regions and list instances and directory associations.

  • cloudwatch – Allows principals to put metric data for the AWS/SSM/JustInTimeAccess namespace.

  • ec2 – Allows principals to describe tags.

To view more details about the policy, including the latest version of the JSON policy document, see AWSSystemsManagerJustInTimeAccessServicePolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSSystemsManagerJustInTimeAccessTokenPolicy

The managed policy AWSSystemsManagerJustInTimeAccessTokenPolicy provides permissions for users to establish secure connections to Amazon EC2 instances and managed instances through Session Manager and Systems Manager GUI Connect RDP connections as part of just-in-time node access workflows.

You can attach AWSSystemsManagerJustInTimeAccessTokenPolicy to your IAM entities.

This policy grants contributor permissions that allow users to start and manage secure sessions, establish RDP connections, and perform necessary cryptographic operations for just-in-time node access.

Permissions details

This policy includes the following permissions.

  • ssm – Allows principals to start Session Manager sessions on Amazon EC2 instances and managed instances using the SSM-SessionManagerRunShell document. Also allows terminating and resuming sessions, retrieving command invocation details, and sending commands to instances for SSO user setup when called through Systems Manager GUI Connect. Additionally allows starting port forwarding sessions for RDP connections when called through Systems Manager GUI Connect.

  • ssmmessages – Allows principals to open data channels for secure communication during Session Manager sessions.

  • ssm-guiconnect – Allows principals to start, get details about, and cancel Systems Manager GUI Connect RDP connections to instances.

  • kms – Allows principals to generate data keys for Session Manager encryption and create grants for RDP connections. These permissions are restricted to Amazon KMS keys tagged with SystemsManagerJustInTimeNodeAccessManaged=true. Grant creation is further restricted to be used only through the Systems Manager GUI Connect service.

  • sso – Allows principals to list directory associations when called through Systems Manager GUI Connect. This is required for RDP SSO user setup.

  • identitystore – Allows principals to describe users in the identity store when called through Systems Manager GUI Connect. This is required for RDP SSO user setup.

To view more details about the policy, including the latest version of the JSON policy document, see AWSSystemsManagerJustInTimeAccessTokenPolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSSystemsManagerJustInTimeAccessTokenSessionPolicy

The managed policy AWSSystemsManagerJustInTimeAccessTokenSessionPolicy allows Systems Manager to apply scoped down permissions to a just-in-time node access token.

You can attach AWSSystemsManagerJustInTimeAccessTokenSessionPolicy to your IAM entities.

This policy grants administrative permissions that allow Systems Manager to scope down permissions for just-in-time node access tokens.

Permissions details

This policy includes the following permissions.

  • ssm – Allows principals to start Session Manager sessions using the SSM-SessionManagerRunShell document. Also when called first via ssm-guiconnect, start sessions using the AWS-StartPortForwardingSession document, list command invocations, and send commands using the AWSSSO-CreateSSOUser document.

  • ssm-guiconnect – Allows principals to cancel, get, and start connections on all resources.

  • kms – Allows principals to create grants and generate data keys for keys tagged with SystemsManagerJustInTimeNodeAccessManaged when called via ssm-guiconnect through an Amazon service.

  • sso – Allows principals to list directory associations when called via ssm-guiconnect.

  • identitystore – Allows principals to describe a user when called via ssm-guiconnect.

To view more details about the policy, including the latest version of the JSON policy document, see AWSSystemsManagerJustInTimeAccessTokenSessionPolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSSystemsManagerJustInTimeNodeAccessRolePropagationPolicy

The managed policy AWSSystemsManagerJustInTimeNodeAccessRolePropagationPolicy allows Systems Manager to share deny-access policies from the delegated administrator account to member accounts, and replicate the policies across multiple Amazon Web Services Regions.

You can attach AWSSystemsManagerJustInTimeNodeAccessRolePropagationPolicy to your IAM entities.

This policy provides the administrative permissions necessary for Systems Manager to share and create deny-access policies. This ensures that deny-access policies are applied to all accounts in an Amazon Organizations organization and Regions configured for just-in-time node access.

Permissions details

This policy includes the following permissions.

  • ssm – Allows principals to manage SSM documents and resource policies.

  • ssm-quicksetup – Allows principals to read Quick Setup configuration managers.

  • organizations – Allows principals to list details about an Amazon Organizations organization and delegated administrators.

  • ram – Allows principals to create, tag, and describe resource shares.

  • iam – Allows principals to describe a service role.

To view more details about the policy, including the latest version of the JSON policy document, see AWSSystemsManagerJustInTimeNodeAccessRolePropagationPolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWSSystemsManagerNotificationsServicePolicy

The managed policy AWSSystemsManagerNotificationsServicePolicy allows Systems Manager to send email notifications for just-in-time node access requests to access request approvers.

You can't attach AWSSystemsManagerJustInTimeAccessServicePolicy to your IAM entities. This policy is attached to a service-linked role that allows Systems Manager to perform actions on your behalf. For more information, see Using roles to send just-in-time node access request notifications.

This policy grants administrative permissions that allow Systems Manager to send email notifications for just-in-time node access requests to access request approvers.

Permissions details

This policy includes the following permissions.

  • identitystore – Allows principals to list and describe users and group membership.

  • sso – Allows principals to list instances, directories, and describe registered Regions.

  • sso-directory – Allows principals to describe users and list members in a group.

  • iam – Allows principals to get information about roles.

To view more details about the policy, including the latest version of the JSON policy document, see AWSSystemsManagerNotificationsServicePolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWS-SSM-Automation-DiagnosisBucketPolicy

The managed policy AWS-SSM-Automation-DiagnosisBucketPolicy provides permissions for diagnosing issues with nodes that interact with Amazon Systems Manager services, by allowing access to S3 buckets that are used for diagnosis and remediation of issues.

You can attach the AWS-SSM-Automation-DiagnosisBucketPolicy policy to your IAM identities. Systems Manager also attaches this policy to an IAM role that allows Systems Manager to perform diagnosis actions on your behalf.

Permissions details

This policy includes the following permissions.

  • s3 – Allows principals to access and write objects to an Amazon S3 bucket.

To view more details about the policy, including the latest version of the JSON policy document, see AWS-SSM-Automation-DiagnosisBucketPolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWS-SSM-RemediationAutomation-OperationalAccountAdministrationRolePolicy

The managed policy AWS-SSM-RemediationAutomation-OperationalAccountAdministrationRolePolicy provides permissions for an operational account to diagnose issues with nodes by providing organization-specific permissions.

You can attach AWS-SSM-RemediationAutomation-OperationalAccountAdministrationRolePolicy to your IAM identities. Systems Manager also attaches this policy to an IAM role that allows Systems Manager to perform diagnosis actions on your behalf.

Permissions details

This policy includes the following permissions.

  • organizations – Allows principals to list a root of the organization, and get member accounts to determine target accounts.

  • sts – Allows principals to assume remediation execution roles to run SSM Automation documents across accounts and Regions, within the same organization.

To view more details about the policy, including the latest version of the JSON policy document, see AWS-SSM-RemediationAutomation-OperationalAccountAdministrationRolePolicy in the Amazon Managed Policy Reference Guide.

Amazon managed policy: AWS-SSM-DiagnosisAutomation-OperationalAccountAdministrationRolePolicy

The managed policy AWS-SSM-DiagnosisAutomation-OperationalAccountAdministrationRolePolicy provides permissions for an operational account to diagnose issues with nodes by providing organization-specific permissions.

You can attach the AWS-SSM-DiagnosisAutomation-OperationalAccountAdministrationRolePolicy policy to your IAM identities. Systems Manager also attaches this policy to an IAM role that allows Systems Manager to perform diagnosis actions on your behalf.

Permissions details

This policy includes the following permissions.

  • organizations – Allows principals to list a root of the organization, and get member accounts to determine target accounts.

  • sts – Allows principals to assume diagnosis execution roles to run SSM Automation documents across accounts and Regions, within the same organization.

To view more details about the policy, including the latest version of the JSON policy document, see AWS-SSM-DiagnosisAutomation-OperationalAccountAdministrationRolePolicy in the Amazon Managed Policy Reference Guide.

Systems Manager updates to Amazon managed policies

In the following table, view details about updates to Amazon managed policies for Systems Manager since this service began tracking these changes on March 12, 2021. For information about other managed policies for the Systems Manager service, see Additional managed policies for Systems Manager later in this topic. For automatic alerts about changes to this page, subscribe to the RSS feed on the Systems Manager Document history page.

Change Description Date

AWSSystemsManagerJustInTimeAccessTokenPolicy – Update to an existing policy

Systems Manager updated the managed policy AWSSystemsManagerJustInTimeAccessTokenPolicy. The statement (SID) TerminateAndResumeSession has been renamed to TerminateAndResumeSessionAndOpenDataChannel and now includes the ssmmessages:OpenDataChannel action, combining session management and data channel permissions into a single statement.

September 25, 2025

Updated managed policies:

Systems Manager updated three managed policies to add support for starting Automation executions on additional Systems Manager resources, including specific Automation runbooks and SSM Command documents.

September 12, 2025

AWSQuickSetupStartStopInstancesExecutionPolicy – Updated managed policy

Systems Manager updated the managed policy to refine permissions for Quick Setup scheduler configuration. The policy now provides more specific permissions for starting and stopping Amazon EC2 instances, accessing change calendars, and executing automation documents with enhanced security conditions.

September 12, 2025

AWSQuickSetupStartSSMAssociationsExecutionPolicy – Updated managed policy

Systems Manager updated the managed policy to change the automation document from AWSQuickSetupType-StartSSMAssociations to AWSQuickSetupType-Scheduler-ChangeCalendarState. This update changes the policy's purpose from starting SSM associations to managing change calendar states for scheduled operations.

September 12, 2025

AmazonSSMAutomationRole – Update to an existing policy

Systems Manager added new permissions to allow Automation runbooks to establish communication channels for session-based operations.

Added the ssmmessages:OpenDataChannel permission for the resource arn:*:ssm:*:*:session/*.

September 11, 2025

AWSSystemsManagerJustInTimeAccessServicePolicy – Updated managed policy

Systems Manager updated the managed policy to add automation execution tagging permissions. The service needs to tag automation executions with SystemsManagerJustInTimeNodeAccessManaged=true tag to enable customers to scope down operator permissions to specific tags.

August 25, 2025

AWSQuickSetupStartSSMAssociationsExecutionPolicy – New policy

Systems Manager added a new policy to allow Quick Setup to run the AWSQuickSetupType-StartSSMAssociations Automation runbook. This runbook is used to start State Manager associations that are created by Quick Setup configurations.

August 12, 2025

AWSQuickSetupStartStopInstancesExecutionPolicy – New policy

Systems Manager added a new policy to allow Quick Setup to start and stop Amazon EC2 instances on a schedule. This policy provides the necessary permissions for the Quick Setup scheduler configuration type to manage instance state based on defined schedules.

August 12, 2025

AWSQuickSetupDeploymentRolePolicy – Update to documentation

Systems Manager has updated the AWSQuickSetupDeploymentRolePolicy managed policy to grant permissions for additional resources. In addition, the documentation for AWSQuickSetupDeploymentRolePolicy has been updated with more detailed descriptions of the permissions granted by this policy for Quick Setup configuration management operations.

August 12, 2025

AWS-SSM-RemediationAutomation-ExecutionRolePolicy – Update to an existing policy

Systems Manager updated the managed policy to improve the security posture of the ssm:StartAutomationExecution API by requiring permissions for both "document" and "automation-execution" resource types. The updated policy provides more comprehensive and detailed permissions for remediation automation execution, including enhanced descriptions for networking remediation capabilities, more specific Amazon VPC endpoint creation permissions, detailed security group management permissions, and improved resource tagging controls for remediation operations.

July 16th, 2025

AWS-SSM-RemediationAutomation-AdministrationRolePolicy – Update to an existing policy

Systems Manager updated the managed policy to support API authorization improvements for remediation automation operations. The updated policy enhances permissions for executing activities defined within Automation documents, with improved security controls and resource access patterns for remediation workflows.

July 16th, 2025

AWS-SSM-DiagnosisAutomation-ExecutionRolePolicy – Update to an existing policy

Systems Manager updated the managed policy to provide more detailed and accurate permissions for diagnosis automation execution. The updated policy includes enhanced descriptions for Amazon EC2 and Amazon VPC resource access, more specific SSM automation permissions, and improved Amazon KMS and IAM permission descriptions with proper resource restrictions.

July 16th, 2025

AWS-SSM-DiagnosisAutomation-AdministrationRolePolicy – Update to an existing policy

Systems Manager updated the managed policy to provide more specific permissions and security conditions for diagnosis automation operations. The updated policy provides enhanced security controls for Amazon KMS key usage, Amazon S3 bucket access, and role assumptions, with stricter resource-based conditions and account-level restrictions.

July 16th, 2025

AWSQuickSetupDeploymentRolePolicy – Update to a policy

Systems Manager added permissions to the managed policy AWSQuickSetupDeploymentRolePolicy for accessing the Amazon owned runbook AWSQuickSetupType-ManageInstanceProfile. This permission makes it possible for Quick Setup to create associations using the managed policy instead of inline policies.

July 14th, 2025

AmazonSSMAutomationRole – Update to documentation

Systems Manager added comprehensive documentation for the existing AmazonSSMAutomationRole policy, which provides permissions for the Systems Manager Automation service to run activities defined within Automation runbooks.

July 15, 2025

AWSSystemsManagerJustInTimeNodeAccessRolePropagationPolicy – Update to an policy

Systems Manager added permissions to allow Systems Manager to tag a resource shared by Amazon Resource Access Manager for just-in-time node access.

April 30th, 2025

AWSQuickSetupManageJITNAResourcesExecutionPolicy – Update to a policy

Systems Manager added permissions to allow Systems Manager to tag IAM roles created for just-in-time node access.

April 30th, 2025

AWSSystemsManagerJustInTimeAccessTokenSessionPolicy – New policy

Systems Manager added a new policy to allow Systems Manager to apply scoped down permissions to a just-in-time node access token.

April 30th, 2025

AWSSystemsManagerNotificationsServicePolicy – New policy

Systems Manager added a new policy to allow Systems Manager to send email notifications for just-in-time node access requests to access request approvers.

April 30th, 2025

AWSSystemsManagerJustInTimeNodeAccessRolePropagationPolicy – New policy

Systems Manager added a new policy to allow Systems Manager to replicate approval policies to different Regions.

April 30th, 2025

AWSSystemsManagerJustInTimeAccessTokenPolicy – New policy

Systems Manager added a new policy to allow Systems Manager to generate access tokens used for just-in-time node access.

April 30th, 2025

AWSSystemsManagerJustInTimeAccessServicePolicy – New policy

Systems Manager added a new policy to provide permissions to Amazon resources managed or used by the Systems Manager just-in-time node access feature.

April 30th, 2025

AWSQuickSetupManageJITNAResourcesExecutionPolicy – New policy

Systems Manager added a new policy to allow Quick Setup, a tool in Systems Manager, to create the IAM roles necessary for just-in-time node access.

April 30th, 2025

AWSQuickSetupJITNADeploymentRolePolicy – New policy

Systems Manager added a new policy that provides permissions that allow Quick Setup to deploy the configuration type required to set up just-in-time node access.

April 30th, 2025

AWSSystemsManagerJustInTimeNodeAccessRolePropagationPolicy – Update to an policy

Systems Manager added permissions to allow Systems Manager to tag a resource shared by Amazon Resource Access Manager for just-in-time node access.

April 30th, 2025

AWSQuickSetupManageJITNAResourcesExecutionPolicy – Update to an policy

Systems Manager added permissions to allow Systems Manager to tag IAM roles created for just-in-time node access.

April 30th, 2025

AWSSystemsManagerJustInTimeAccessTokenSessionPolicy – New policy

Systems Manager added a new policy to allow Systems Manager to apply scoped down permissions to a just-in-time node access token.

April 30th, 2025

AWSSystemsManagerNotificationsServicePolicy – New policy

Systems Manager added a new policy to allow Systems Manager to send email notifications for just-in-time node access requests to access request approvers.

April 30th, 2025

AWSSystemsManagerJustInTimeNodeAccessRolePropagationPolicy – New policy

Systems Manager added a new policy to allow Systems Manager to replicate approval policies to different Regions.

April 30th, 2025

AWSSystemsManagerJustInTimeAccessTokenPolicy – New policy

Systems Manager added a new policy to allow Systems Manager to generate access tokens used for just-in-time node access.

April 30th, 2025

AWSSystemsManagerJustInTimeAccessServicePolicy – New policy

Systems Manager added a new policy to provide permissions to Amazon resources managed or used by the Systems Manager just-in-time node access feature.

April 30th, 2025

AWSQuickSetupManageJITNAResourcesExecutionPolicy – New policy

Systems Manager added a new policy to allow Quick Setup, a tool in Systems Manager, to create the IAM roles necessary for just-in-time node access.

April 30th, 2025

AWSQuickSetupJITNADeploymentRolePolicy – New policy

Systems Manager added a new policy that provides permissions that allow Quick Setup to deploy the configuration type required to set up just-in-time node access.

April 30th, 2025

AWS-SSM-DiagnosisAutomation-OperationalAccountAdministrationRolePolicy – New policy

Systems Manager added a new policy that provides permissions for an operational account to diagnose issues with nodes by providing organization-specific permissions.

November 21, 2024

AWS-SSM-RemediationAutomation-OperationalAccountAdministrationRolePolicy – New policy

Systems Manager added a new policy that provides permissions for an operational account to diagnose issues with nodes by providing organization-specific permissions.

November 21, 2024

AWS-SSM-Automation-DiagnosisBucketPolicy – New policy

Systems Manager added a new policy to support starting Automation workflows that diagnose issues with managed nodes in targeted accounts and Regions.

November 21, 2024

AmazonSSMServiceRolePolicy – Update to an existing policy

Systems Manager added new permissions to allow Amazon Resource Explorer to gather details about Amazon EC2 instances and display the results in widgets in the new Systems Manager Dashboard.

November 21, 2024
SSMQuickSetupRolePolicy – Update to an existing policy Systems Manager has updated the managed policy SSMQuickSetupRolePolicy. This updates allows the associated service-linked role AWSServiceRoleForSSMQuickSetup to manage resource data syncs. November 21, 2024
AWS-SSM-DiagnosisAutomation-AdministrationRolePolicy – New policy Systems Manager added a new policy to support starting Automation workflows that diagnose issues with managed nodes in targeted account and Regions. November 21, 2024
AWS-SSM-DiagnosisAutomation-ExecutionRolePolicy – New policy Systems Manager added a new policy to support starting Automation workflows that diagnose issues with managed nodes in a targeted account and Region. November 21, 2024
AWS-SSM-RemediationAutomation-AdministrationRolePolicy – New policy Systems Manager added a new policy to support starting Automation workflows that remediate issues in managed nodes in targeted accounts and Regions. November 21, 2024
AWS-SSM-RemediationAutomation-ExecutionRolePolicy – New policy Systems Manager added a new policy to support starting Automation workflows that remediate issues in managed nodes in a targeted account and Region. November 21, 2024

AWSQuickSetupSSMDeploymentRolePolicy – Update to an policy

Systems Manager added permissions to allow Systems Manager to tag IAM roles and Lambda created for the unified console.

May 7th, 2025
AWSQuickSetupSSMManageResourcesExecutionPolicy – New policy Systems Manager added a new policy to support running an operation in Quick Setup that creates IAM roles for Quick Setup associations, which in turn are created by a AWSQuickSetupType-SSM deployment. November 21, 2024
AWSQuickSetupSSMLifecycleManagementExecutionPolicy – New policy Systems Manager added a new policy to support Quick Setup running a Amazon CloudFormation custom resource on lifecycle events during a Quick Setup deployment. November 21, 2024
AWSQuickSetupSSMDeploymentRolePolicy – New policy Systems Manager added a new policy to support granting administrative permissions that allow Quick Setup to create resources that are using during the Systems Manager onboarding process. November 21, 2024
AWSQuickSetupSSMDeploymentS3BucketRolePolicy – New policy Systems Manager added a new policy to support managing and retrieving information about specific buckets in the principal account that are managed through Amazon CloudFormation templates November 21, 2024
AWSQuickSetupEnableDHMCExecutionPolicy – New policy Systems Manager is introducing a new policy to allow Quick Setup to create an IAM role that itself uses the existing AmazonSSMManagedEC2InstanceDefaultPolicy. This policy contains all the permissions required for SSM Agent to communicate with Systems Manager service. The new policy also allows modifications to the Systems Manager service settings. November 21, 2024
AWSQuickSetupEnableAREXExecutionPolicy – New policy Systems Manager added a new policy to allow Quick Setup to create a service-linked role for Amazon Resource Explorer, for accessing Resource Explorer views and aggregator indexes. November 21, 2024
AWSQuickSetupManagedInstanceProfileExecutionPolicy – New policy

Systems Manager added a new policy to allow Quick Setup to create a default Quick Setup instance profile and to attach it to any Amazon EC2 instances that lack an associated instance profile. This new policy also allows Quick Setup to attach permissions to existing profiles to ensure that all required Systems Manager permissions have been granted.

November 21, 2024

SSMQuickSetupRolePolicy – Update to an existing policy

Systems Manager added new permissions to allow Quick Setup to check the health of additional Amazon CloudFormation stack sets that it has created.

August 13, 2024
AmazonSSMManagedEC2InstanceDefaultPolicy – Update to an existing policy Systems Manager has added statement IDs (Sids) to the JSON policy for AmazonSSMManagedEC2InstanceDefaultPolicy. These Sids provide inline descriptions of the purpose of each policy statement. July 18, 2024
SSMQuickSetupRolePolicy – New policy Systems Manager added a new policy to allow Quick Setup to check the health of deployed resources and remediate instances that have drifted from the original configuration. July 3, 2024
AWSQuickSetupDeploymentRolePolicy – New policy Systems Manager added a new policy to support multiple Quick Setup configuration types that create IAM roles and automations, which in turn configure frequently used Amazon Web Services services and features with recommended best practices. July 3, 2024

AWSQuickSetupPatchPolicyDeploymentRolePolicy

– New policy

Systems Manager added a new policy to allow Quick Setup to create resources associated with Patch Manager patch policy Quick Setup configurations.

July 3, 2024

AWSQuickSetupPatchPolicyBaselineAccess – New policy

Systems Manager added a new policy to allow Quick Setup to access patch baselines in Patch Manager with read-only permissions.

July 3, 2024
AWSSystemsManagerEnableExplorerExecutionPolicy – New policy Systems Manager added a new policy to allow Quick Setup to grant administrative permissions for enabling Explorer. July 3, 2024
AWSSystemsManagerEnableConfigRecordingExecutionPolicy – New policy Systems Manager added a new policy to allow Quick Setup to enable and configure Amazon Config configuration recording. July 3, 2024

AWSQuickSetupDevOpsGuruPermissionsBoundary – New policy

Systems Manager added a new policy to allow Quick Setup to enable and configure Amazon DevOps Guru.

July 3, 2024

AWSQuickSetupDistributorPermissionsBoundary – New policy

Systems Manager added a new policy to allow Quick Setup to enable and configure Distributor, a tool in Amazon Systems Manager.

July 3, 2024

AWSQuickSetupSSMHostMgmtPermissionsBoundary – New policy

Systems Manager added a new policy to allow Quick Setup to enable and configure Systems Manager tools for securely managing Amazon EC2 instances.

July 3, 2024

AWSQuickSetupPatchPolicyPermissionsBoundary – New policy

Systems Manager added a new policy to allow Quick Setup to enable and configure patch policies in Patch Manager, a tool in Amazon Systems Manager.

July 3, 2024

AWSQuickSetupSchedulerPermissionsBoundary – New policy

Systems Manager added a new policy to allow Quick Setup to enable and configure scheduled operations on Amazon EC2 instances and other resources.

July 3, 2024

AWSQuickSetupCFGCPacksPermissionsBoundary – New policy

Systems Manager added a new policy to allow Quick Setup to deploy Amazon Config conformance packs.

July 3, 2024

AWSSystemsManagerOpsDataSyncServiceRolePolicy – Update to an existing policy

OpsCenter updated the policy to improve the security of the service code within the service-linked role for Explorer to manage OpsData-related operations. July 3, 2023

AmazonSSMManagedEC2InstanceDefaultPolicy – New policy

Systems Manager added a new policy to allow Systems Manager functionality on Amazon EC2 instances without the use of an IAM instance profile.

August 18, 2022

AmazonSSMServiceRolePolicy – Update to an existing policy

Systems Manager added new permissions to allow Explorer to create a managed rule when you turn on Security Hub from Explorer or OpsCenter. New permissions were added to check that config and the compute-optimizer meet the necessary requirements before allowing OpsData.

April 27, 2021

AWSSystemsManagerOpsDataSyncServiceRolePolicy – New policy

Systems Manager added a new policy to create and update OpsItems and OpsData from Security Hub findings in Explorer and OpsCenter.

April 27, 2021

AmazonSSMServiceRolePolicy – Update to an existing policy

Systems Manager added new permissions to allow viewing aggregate OpsData and OpsItems details from multiple accounts and Amazon Web Services Regions in Explorer.

March 24, 2021

Systems Manager started tracking changes

Systems Manager started tracking changes for its Amazon managed policies.

March 12, 2021

Additional managed policies for Systems Manager

In addition to the managed policies described earlier in this topic, the following policies are also supported by Systems Manager.