My Admin Account (and Root Account) do not have full permissions

0

Hi, I'm trying to access various parts of the AWS Console and am getting this:

Contact your AWS administrator if you need help. If you are an AWS administrator, you can provide permissions for your users or groups by creating IAM policies.

The problem is, I'm using the AWS Admin account with "AdministratorAccess", which should have access to all functionality. Do you know why this isn't working? Thanks!

AlexC
질문됨 2달 전235회 조회
1개 답변
1

Is your account a member account in a AWS Organization and is it possible there's a SCP in place? "An SCP restricts permissions for IAM users and roles in member accounts, including the member account's root user. Any account has only those permissions permitted by every parent above it. If a permission is blocked at any level above the account, either implicitly (by not being included in an Allow policy statement) or explicitly (by being included in a Deny policy statement), a user or role in the affected account can't use that permission, even if the account administrator attaches the AdministratorAccess IAM policy with / permissions to the user."

https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html

AWS
답변함 2달 전
profile pictureAWS
전문가
검토됨 2달 전
  • Thank you! This is very helpful and makes sense, but where do I go to actually see if an SPC is denying the policy even in my root/admin accounts? Is there a specific setting? I followed your link to the articles, but I'm struggling with finding out how to correct the permissions. Thank you!!

  • Hi AlexC. Access the SCPs from the AWS Organizations console. The steps are here [1].

    [1] https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps_create.html

  • Hi, Jose! Thanks for your response. When I click "Organization" (upper right-hand side of the screen), I get a page about what organizations are. On the left-hand side of that page is an option for "Invitations." I click on that and it says there are no invitations. I don't think I have any organizations assigned to any of my accounts (root or admin).

  • Hi, there! I'm still really struggling with this. Can I get additional direction and ideas as to what to do? Thank you!

  • Jose- I used Incognito to access the portal. I went to:

    Billing and Cost Management

    It shows "Month-to-date Cost - Access Denied."

    I clicked on "Access Denied"

    A window surfaced that featured text to give to my "Administrator" (even though I am the administrator :)

    Here is the text: User: [my user account number is here] Service: [Cost Explorer] Name: [AccessDeniedException] HTTP status code: [400] Context: [IAM user access not activated] Request ID: [this is a unique number I didn't want to cut/paste into this message]

    Any thoughts? Thanks again for your help!

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠