AWS Billing AWS fine grain IAM actions

0

Manage IAM Migration When i'm trying to migrate Billing IAm policy. It is giving me this promt "Failed to save changes to policy . Cannot perform the operation on the protected role 'AWSReservedSSO_data_warehouse_user_557f144c404dfcb9' - this role is only modifiable by AWS" Does AWS Takes care of this policy or do i have to take any action on this? i'm unable to fine that policy in my account either in roles or policies and users too. And for all the administrator access role will AWS itself migrate the policies?

1 個回答
0

Hey Sravya,

This is an IAM Role that was created through the AWS IAM Identity Center service. It looks like you're trying to modify the inline policy on the role. This is deemed a change to the IAM Role itself, and cannot be done from the IAM console.

In order to modify the inline policy on an IAM Role that was provisioned by the IAM Identity Center (IdC) service, you will need to go to the IAM IdC administrator console, modify the Permission Set that created the IAM Role, and then push the change out to the account(s) that you want to see the change on. If you have an AWS Admin in your company who controls the administration of the IAM IdC service, then you will need to reach out to them to make this change, as it can only be made from the Management account of the organisation in AWS Organizations, or the delegated administration account for IAM IdC.

For clarity - the only IAM Roles and Policies that AWS will automatically update on your behalf are IAM Roles that are provisioned by services), and the AWS Managed IAM Policies - both of which you will be notified of in your PHD (Personal Health Dashboard) in advance of the change being made.

profile pictureAWS
已回答 7 個月前
profile picture
專家
Kallu
已審閱 6 個月前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南