ec2:CreateNetworkInterface
Literal appearances in AWS managed IAM policies. Statements that use wildcards (for example s3:*) are not counted here. This is not an IAM authorization simulation.
Policies (any)
113
Allow (Action)
113
Deny (Action)
0
NotAction
4
Index generated 4/7/2026, 3:29:24 AM. 559 policies include at least one wildcard action string (any service).
Action reference
SAR-style (unofficial)Service: Amazon EC2
Access level
WriteDescription
Grants permission to create a network interface in a subnet
Resource types
- network-interface*
- subnet*
- security-group
Dependent actions
- ec2:CreateTags
Allow (Action)
- APIGatewayServiceRolePolicy
- AWSApplicationMigrationNetworkMigrationMultiAccount
- AWSCloudFrontVPCOriginServiceRolePolicy
- AWSCloudHSMRole
- AWSDataPipelineRole
- AWSDataSyncFullAccess
- AWSDeviceFarmServiceRolePolicy
- AWSDeviceFarmTestGridServiceRolePolicy
- AWSDirectoryServiceFullAccess
- AWSElasticDisasterRecoveryConsoleFullAccess_v2
- AWSElasticDisasterRecoveryServiceRolePolicy
- AWSElasticLoadBalancingClassicServiceRolePolicy
- AWSElasticLoadBalancingServiceRolePolicy
- AWSFaultInjectionSimulatorNetworkAccess
- AWSGlobalAcceleratorSLRPolicy
- AWSGlueConsoleSageMakerNotebookFullAccess
- AWSGlueDataBrewServiceRole
- AWSGlueServiceRole
- AWSHealthOmicsServiceLinkedRolePolicy
- AWSKeyManagementServiceCustomKeyStoresServiceRolePolicy
- AWSLambdaENIManagementAccess
- AWSLambdaMSKExecutionRole
- AWSLambdaManagedEC2ResourceOperator
- AWSLambdaVPCAccessExecutionRole
- AWSM2ServicePolicy
- AWSOutpostsServiceRolePolicy
- AWSPCSServiceRolePolicy
- AWSS3OnOutpostsServiceRolePolicy
- AWSVPCTransitGatewayServiceRolePolicy
- AWSVPCVerifiedAccessServiceRolePolicy
- AWSVpcLatticeServiceRolePolicy
- AmazonAppStreamServiceAccess
- AmazonApplicationWizardFullaccess
- AmazonDMSVPCManagementRole
- AmazonDRSVPCManagement
- AmazonDataZoneEnvironmentRolePermissionsBoundary
- AmazonDataZoneProjectRolePermissionsBoundary
- AmazonDataZoneSageMakerEnvironmentRolePermissionsBoundary
- AmazonDocDBConsoleFullAccess
- AmazonECSServiceRolePolicy
- AmazonEKSForFargateServiceRolePolicy
- AmazonEKSLocalOutpostServiceRolePolicy
- AmazonEKSNetworkingPolicy
- AmazonEKSServicePolicy
- AmazonEKSServiceRolePolicy
- AmazonEKSVPCResourceController
- AmazonEKS_CNI_Policy
- AmazonEMRServerlessServiceRolePolicy
- AmazonEMRServicePolicy_v2
- AmazonEVSServiceRolePolicy
- AmazonElasticFileSystemFullAccess
- AmazonElasticFileSystemServiceRolePolicy
- AmazonElasticMapReduceEditorsRole
- AmazonElasticMapReduceRole
- AmazonElasticsearchServiceRolePolicy
- AmazonFSxServiceRolePolicy
- AmazonGrafanaServiceLinkedRolePolicy
- AmazonLaunchWizardFullAccessV2
- AmazonLaunchWizardFullaccess
- AmazonLaunchWizard_Fullaccess
- AmazonMQApiFullAccess
- AmazonMQFullAccess
- AmazonMWAAServerlessServiceRolePolicy
- AmazonMWAAServiceRolePolicy
- AmazonNimbleStudio-StudioAdmin
- AmazonNimbleStudio-StudioUser
- AmazonOpenSearchServiceRolePolicy
- AmazonPrometheusScraperServiceRolePolicy
- AmazonRDSBetaServiceRolePolicy
- AmazonRDSCustomPreviewServiceRolePolicy
- AmazonRDSCustomServiceRolePolicy
- AmazonRDSPreviewServiceRolePolicy
- AmazonRDSServiceRolePolicy
- AmazonRedshiftServiceLinkedRolePolicy
- AmazonRoute53ResolverFullAccess
- AmazonSageMakerCoreServiceRolePolicy
- AmazonSageMakerFullAccess
- AmazonSageMakerHyperPodInferenceAccess
- AmazonSageMakerNotebooksServiceRolePolicy
- AmazonSageMakerQuickSightVPCPolicy
- AmazonTimestreamInfluxDBFullAccess
- AmazonTimestreamInfluxDBFullAccessWithoutMarketplaceAccess
- AmazonTimestreamInfluxDBServiceRolePolicy
- AmazonVPCCrossAccountNetworkInterfaceOperations
- AmazonVPCFullAccess
- AmazonWorkLinkServiceRolePolicy
- AmazonWorkMailFullAccess
- AmazonWorkSpacesServiceAccess
- AmazonWorkSpacesWebServiceRolePolicy
- AmazonZocaloFullAccess
- AppRunnerNetworkingServiceRolePolicy
- BedrockAgentCoreNetworkServiceRolePolicy
- ClientVPNServiceRolePolicy
- DAXServiceRolePolicy
- Ec2InstanceConnectEndpoint
- ElastiCacheServiceRolePolicy
- KafkaConnectServiceRolePolicy
- KafkaServiceRolePolicy
- MemoryDBServiceRolePolicy
- NeptuneConsoleFullAccess
- NetworkAdministrator
- RTBFabricServiceRolePolicy
- SageMakerStudioAdminIAMDefaultExecutionPolicy
- SageMakerStudioAdminIAMPermissiveExecutionPolicy
- SageMakerStudioEMRServiceRolePolicy
- SageMakerStudioProjectProvisioningRolePolicy
- SageMakerStudioProjectRoleMachineLearningPolicy
- SageMakerStudioProjectUserRolePermissionsBoundary
- SageMakerStudioProjectUserRolePolicy
- SageMakerStudioUserIAMDefaultExecutionPolicy
- SageMakerStudioUserIAMPermissiveExecutionPolicy
- SystemAdministrator
- WorkLinkServiceRolePolicy
Deny (Action)
None
Thanks to Ian McKay for iam-dataset (MIT), structured data derived from the AWS Service Authorization Reference. Not maintained by AWS and not guaranteed current. IAMTrail's managed policy archive is separate.
Definitions bundle generated 4/7/2026, 3:29:24 AM