Skip to content

Commit 96b2a82

Browse files
authored
Give SSO developer role IAM read access (#1260)
The PowerUserAccess policy does not allow access to IAM, From the docs[1].. `Provides full access to AWS services and resources, but does not allow management of Users and groups.` Developers should be able to view AWS user and group info. [1] https://docs.aws.amazon.com/aws-managed-policy/latest/reference/PowerUserAccess.html
1 parent 222bfba commit 96b2a82

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

org-formation/700-aws-sso/_tasks.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -410,6 +410,7 @@ SsoDeveloper:
410410
permissionSetName: 'Developer'
411411
managedPolicies:
412412
- 'arn:aws:iam::aws:policy/PowerUserAccess'
413+
- 'arn:aws:iam::aws:policy/IAMReadOnlyAccess'
413414
- 'arn:aws:iam::aws:policy/AdministratorAccess-AWSElasticBeanstalk'
414415
- 'arn:aws:iam::aws:policy/AWSBillingReadOnlyAccess'
415416
- 'arn:aws:iam::aws:policy/AmazonBedrockFullAccess'

0 commit comments

Comments
 (0)