AWS Billing AWS fine grain IAM actions

0

Manage IAM Migration When i'm trying to migrate Billing IAm policy. It is giving me this promt "Failed to save changes to policy . Cannot perform the operation on the protected role 'AWSReservedSSO_data_warehouse_user_557f144c404dfcb9' - this role is only modifiable by AWS" Does AWS Takes care of this policy or do i have to take any action on this? i'm unable to fine that policy in my account either in roles or policies and users too. And for all the administrator access role will AWS itself migrate the policies?

1개 답변
0

Hey Sravya,

This is an IAM Role that was created through the AWS IAM Identity Center service. It looks like you're trying to modify the inline policy on the role. This is deemed a change to the IAM Role itself, and cannot be done from the IAM console.

In order to modify the inline policy on an IAM Role that was provisioned by the IAM Identity Center (IdC) service, you will need to go to the IAM IdC administrator console, modify the Permission Set that created the IAM Role, and then push the change out to the account(s) that you want to see the change on. If you have an AWS Admin in your company who controls the administration of the IAM IdC service, then you will need to reach out to them to make this change, as it can only be made from the Management account of the organisation in AWS Organizations, or the delegated administration account for IAM IdC.

For clarity - the only IAM Roles and Policies that AWS will automatically update on your behalf are IAM Roles that are provisioned by services), and the AWS Managed IAM Policies - both of which you will be notified of in your PHD (Personal Health Dashboard) in advance of the change being made.

profile pictureAWS
답변함 6달 전
profile picture
전문가
Kallu
검토됨 6달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인