IAM Policy Simulator moves to the IAM console and adds additional capabilities
News
This article announces a major update to IAM Policy Simulator, moving it into the IAM console and adding new testing capabilities.
- IAM Policy Simulator now integrated directly into the IAM console for unified policy management
- Can test service control policies (SCPs) and their interaction with identity and resource policies
- Test condition keys like Region restrictions and tag requirements through the API
- Exclude specific policies to model "what if" removal scenarios
- Cross-account simulations now report per-policy decisions with matched statements for denied requests
These enhancements enable teams to automate policy testing, detect over-permissive access, and validate guardrails more effectively across all AWS Regions.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.