

# IAM：访问策略模拟器控制台
<a name="reference_policies_examples_iam_policy-sim-console"></a>

此示例说明您如何创建基于身份的策略，以允许对附加到当前 Amazon Web Services 账户 中的用户、组或角色的策略使用策略模拟器控制台。此策略授予有计划地通过 Amazon API 或 Amazon CLI 完成此操作的必要权限。

您可以在以下位置访问 IAM policy simulator 控制台：[https://policysim.aws.amazon.com/](https://policysim.aws.amazon.com/)

------
#### [ JSON ]

****  

```
{
    "Version":"2012-10-17",		 	 	 
    "Statement": [
        {
            "Action": [
                "iam:GetGroup",
                "iam:GetGroupPolicy",
                "iam:GetPolicy",
                "iam:GetPolicyVersion",
                "iam:GetRole",
                "iam:GetRolePolicy",
                "iam:GetUser",
                "iam:GetUserPolicy",
                "iam:ListAttachedGroupPolicies",
                "iam:ListAttachedRolePolicies",
                "iam:ListAttachedUserPolicies",
                "iam:ListGroups",
                "iam:ListGroupPolicies",
                "iam:ListGroupsForUser",
                "iam:ListRolePolicies",
                "iam:ListRoles",
                "iam:ListUserPolicies",
                "iam:ListUsers"
            ],
            "Effect": "Allow",
            "Resource": "*"
        }
    ]
}
```

------