IAM Policy Simulator moves to the IAM console and adds additional capabilities
News
This article announces a major update to IAM Policy Simulator, moving it into the IAM console and adding new testing capabilities.
- IAM Policy Simulator now integrated directly into the IAM console for unified policy management
- Can test service control policies (SCPs) and their interaction with identity and resource policies
- Test condition keys like Region restrictions and tag requirements through the API
- Exclude specific policies to model "what if" removal scenarios
- Cross-account simulations now report per-policy decisions with matched statements for denied requests
These enhancements enable teams to automate policy testing, detect over-permissive access, and validate guardrails more effectively across all AWS Regions.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
May 8
2026
2026
IAM Policy Autopilot adds Java support and Terraform-aware policy generation
Jan 14
2025
2025
How to implement IAM policy checks with Visual Studio Code and IAM Access Analyzer
Jun 11
2024
2024
IAM Access Analyzer Update: Extending custom policy checks & guided revocation
Feb 28
2025
2025
AWS Network Firewall simplifies policy management with enhanced console features
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.