Amazon S3 adds additional policy details to access denied error messages
News
Amazon S3 now includes specific IAM and AWS Organizations policy ARNs in HTTP 403 Access Denied error messages for same-account and same-organization requests.
- Error messages now show the specific policy ARN responsible for explicit deny cases
- Covers Service Control Policies (SCPs), Resource Control Policies (RCPs), identity-based policies, session policies, and permission boundaries
- Eliminates manual inspection of multiple policies to identify root cause
- Available in all AWS Regions including GovCloud and China Regions
This enhancement streamlines troubleshooting of S3 access denied errors by providing precise policy identification.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Jan 21
2026
2026
AWS introduces additional policy details to access denied error messages
Aug 21
2024
2024
Amazon S3 adds additional context to HTTP 403 Access Denied error messages
Jun 16
2025
2025
Amazon S3 extends additional context for HTTP 403 Access Denied error messages to AWS Organizations
Aug 7
2026
2026
Securing your Amazon S3 buckets: Identifying and remediating over-permissioned access
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.