logo

Can I do that with policy? Understanding the AWS Service Authorization Reference

ID: 9de2c424-17c9-52da-9eb1-468a91c65a4c

STIX ID: report--9de2c424-17c9-52da-9eb1-468a91c65a4c

Feed Name: AWS Security Blog

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: Anshu Bathla

...
...

This blog post explains how to use the AWS Service Authorization Reference to determine what information is available in the authorization context and therefore what AWS IAM policies can enforce. It provides examples (S3 server-side encryption, EC2 instance and network restrictions, DynamoDB fine-grained access) and highlights scenarios—such as restricting security group CIDR rules or Lambda memory size—where IAM cannot enforce the desired control, recommending detective or automated responses (AWS Config, EventBridge, Lambda) and a layered security approach.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.