ec2:CreateTags
Literal appearances in AWS managed IAM policies. Statements that use wildcards (for example s3:*) are not counted here. This is not an IAM authorization simulation.
Policies (any)
167
Allow (Action)
167
Deny (Action)
2
NotAction
3
Index generated 4/7/2026, 3:29:24 AM. 559 policies include at least one wildcard action string (any service).
Action reference
SAR-style (unofficial)Service: Amazon EC2
Access level
TaggingDescription
Grants permission to add or overwrite one or more tags for Amazon EC2 resources
Resource types (first 30)
- capacity-block
- capacity-manager-data-export
- capacity-reservation
- capacity-reservation-fleet
- carrier-gateway
- client-vpn-endpoint
- coip-pool
- customer-gateway
- declarative-policies-report
- dedicated-host
- dhcp-options
- egress-only-internet-gateway
- elastic-gpu
- elastic-ip
- export-image-task
- export-instance-task
- fleet
- fpga-image
- host-reservation
- image
- image-usage-report
- import-image-task
- import-snapshot-task
- instance
- instance-connect-endpoint
- instance-event-window
- internet-gateway
- ipam
- ipam-external-resource-verification-token
- ipam-policy
Allow (Action)
- APIGatewayServiceRolePolicy
- AWS-SSM-RemediationAutomation-ExecutionRolePolicy
- AWSApplicationMigrationEC2Access
- AWSApplicationMigrationNetworkMigrationMultiAccount
- AWSApplicationMigrationReplicationServerPolicy
- AWSApplicationMigrationServiceRolePolicy
- AWSBackupServiceLinkedRolePolicyForBackup
- AWSBackupServiceRolePolicyForBackup
- AWSBackupServiceRolePolicyForRestores
- AWSBatchServiceRole
- AWSCloud9ServiceRolePolicy
- AWSCloudFrontVPCOriginServiceRolePolicy
- AWSCloudHSMRole
- AWSConnector
- AWSDataLifecycleManagerServiceRole
- AWSDataLifecycleManagerServiceRoleForAMIManagement
- AWSDataPipelineRole
- AWSDeepRacerCloudFormationAccessPolicy
- AWSDeviceFarmServiceRolePolicy
- AWSDeviceFarmTestGridServiceRolePolicy
- AWSDirectoryServiceFullAccess
- AWSEC2CapacityReservationFleetRolePolicy
- AWSEC2FleetServiceRolePolicy
- AWSEC2SpotFleetServiceRolePolicy
- AWSEC2SpotServiceRolePolicy
- AWSEC2VssRestorePolicy
- AWSEC2VssSnapshotPolicy
- AWSElasticBeanstalkCustomPlatformforEC2Role
- AWSElasticBeanstalkRoleCore
- AWSElasticDisasterRecoveryConsoleFullAccess
- AWSElasticDisasterRecoveryConsoleFullAccess_v2
- AWSElasticDisasterRecoveryReplicationServerPolicy
- AWSElasticDisasterRecoveryServiceRolePolicy
- AWSFaultInjectionSimulatorNetworkAccess
- AWSGlobalAcceleratorSLRPolicy
- AWSGlueConsoleFullAccess
- AWSGlueConsoleSageMakerNotebookFullAccess
- AWSGlueDataBrewServiceRole
- AWSGlueServiceNotebookRole
- AWSGlueServiceRole
- AWSHealthOmicsServiceLinkedRolePolicy
- AWSIoTDeviceTesterForFreeRTOSFullAccess
- AWSLambdaManagedEC2ResourceOperator
- AWSLicenseManagerUserSubscriptionsServiceRolePolicy
- AWSMarketplaceFullAccess
- AWSMarketplaceImageBuildFullAccess
- AWSMigrationHubDiscoveryAccess
- AWSMigrationHubRefactorSpaces-SSMAutomationPolicy
- AWSNetworkFirewallServiceRolePolicy
- AWSObservabilityAdminTelemetryEnablementServiceRolePolicy
- AWSOpsWorksCMServiceRole
- AWSPCSServiceRolePolicy
- AWSQuickSetupPatchPolicyPermissionsBoundary
- AWSRefactoringToolkitFullAccess
- AWSS3OnOutpostsServiceRolePolicy
- AWSSSMForSAPServiceLinkedRolePolicy
- AWSServiceRoleForAmazonEKSNodegroup
- AWSServiceRoleForEC2ScheduledInstances
- AWSServiceRoleForGammaInternalAmazonEKSNodegroup
- AWSServiceRoleForImageBuilder
- AWSServiceRoleForSMS
- AWSThinkboxAWSPortalAdminPolicy
- AWSThinkboxDeadlineSpotEventPluginAdminPolicy
- AWSTransformApplicationDeploymentPolicy
- AWSVPCVerifiedAccessServiceRolePolicy
- AWSVpcLatticeServiceRolePolicy
- AdministratorAccess-AWSElasticBeanstalk
- AmazonApplicationWizardFullaccess
- AmazonDataZoneEnvironmentRolePermissionsBoundary
- AmazonDataZoneProjectDeploymentPermissionsBoundary
- AmazonDataZoneProjectRolePermissionsBoundary
- AmazonDynamoDBFullAccesswithDataPipeline
- AmazonEBSCSIDriverPolicy
- AmazonEC2RolePolicyForApplicationWizard
- AmazonEC2RolePolicyForLaunchWizard
- AmazonEC2SpotFleetTaggingRole
- AmazonECSInfrastructureRolePolicyForManagedInstances
- AmazonECSInfrastructureRolePolicyForVolumes
- AmazonECSInfrastructureRoleforExpressGatewayServices
- AmazonECSServiceRolePolicy
- AmazonEKSBlockStoragePolicy
- AmazonEKSClusterPolicy
- AmazonEKSComputePolicy
- AmazonEKSLoadBalancingPolicy
- AmazonEKSLocalOutpostServiceRolePolicy
- AmazonEKSNetworkingPolicy
- AmazonEKSServicePolicy
- AmazonEKSServiceRolePolicy
- AmazonEKS_CNI_Policy
- AmazonEMRServicePolicy_v2
- AmazonEVSServiceRolePolicy
- AmazonElastiCacheFullAccess
- AmazonElasticMapReduceEditorsRole
- AmazonElasticMapReduceFullAccess
- AmazonElasticMapReduceRole
- AmazonElasticsearchServiceRolePolicy
- AmazonFSxConsoleFullAccess
- AmazonFSxFullAccess
- AmazonFSxServiceRolePolicy
- AmazonGrafanaServiceLinkedRolePolicy
- AmazonGuardDutyMalwareProtectionServiceRolePolicy
- AmazonGuardDutyServiceRolePolicy
- AmazonInspector2AgentlessServiceRolePolicy
- AmazonLambdaRolePolicyForLaunchWizardSAP
- AmazonLaunchWizardFullAccessV2
- AmazonLaunchWizardFullaccess
- AmazonLaunchWizard_Fullaccess
- AmazonMQServiceRolePolicy
- AmazonMSKFullAccess
- AmazonMWAAServiceRolePolicy
- AmazonOpenSearchIngestionServiceRolePolicy
- AmazonOpenSearchServiceRolePolicy
- AmazonPrometheusScraperServiceRolePolicy
- AmazonRDSCustomInstanceProfileRolePolicy
- AmazonRDSCustomPreviewServiceRolePolicy
- AmazonRDSCustomServiceRolePolicy
- AmazonRedshiftServiceLinkedRolePolicy
- AmazonSSMAutomationRole
- AmazonSageMakerNotebooksServiceRolePolicy
- AmazonTimestreamInfluxDBServiceRolePolicy
- AmazonVPCFullAccess
- AmazonVPCNetworkAccessAnalyzerFullAccessPolicy
- AmazonVPCReachabilityAnalyzerFullAccessPolicy
- AmazonWorkMailFullAccess
- AmazonWorkSpacesWebServiceRolePolicy
- AmazonZocaloFullAccess
- AppRunnerNetworkingServiceRolePolicy
- AutoScalingServiceRolePolicy
- AwsGlueSessionUserRestrictedNotebookServiceRole
- AwsGlueSessionUserRestrictedServiceRole
- BatchServiceRolePolicy
- BedrockAgentCoreNetworkServiceRolePolicy
- ComputeOptimizerAutomationServiceRolePolicy
- DataScientist
- EC2FastLaunchFullAccess
- EC2FastLaunchServiceRolePolicy
- EC2FleetTimeShiftableServiceRolePolicy
- EC2ImageBuilderLifecycleExecutionPolicy
- EC2InstanceProfileForImageBuilder
- Ec2ImageBuilderCrossAccountDistributionAccess
- Ec2InstanceConnectEndpoint
- ElastiCacheServiceRolePolicy
- FMSServiceRolePolicy
- KafkaConnectServiceRolePolicy
- MemoryDBServiceRolePolicy
- MigrationHubServiceRolePolicy
- NetworkAdministrator
- ROSAAmazonEBSCSIDriverOperatorPolicy
- ROSAControlPlaneOperatorPolicy
- ROSAInstallerPolicy
- ROSAKubeControllerPolicy
- ROSANodePoolManagementPolicy
- ROSASharedVPCEndpointPolicy
- RTBFabricServiceRolePolicy
- ResourceGroupsTaggingAPITagUntagSupportedResources
- SageMakerStudioAdminIAMConsolePolicy
- SageMakerStudioAdminIAMDefaultExecutionPolicy
- SageMakerStudioAdminIAMPermissiveExecutionPolicy
- SageMakerStudioProjectProvisioningRolePolicy
- SageMakerStudioProjectUserRolePermissionsBoundary
- SageMakerStudioProjectUserRolePolicy
- SageMakerStudioUserIAMDefaultExecutionPolicy
- SageMakerStudioUserIAMPermissiveExecutionPolicy
- ServerMigrationServiceLaunchRole
- ServerMigrationServiceRole
- ServerMigration_ServiceRole
- SystemAdministrator
Thanks to Ian McKay for iam-dataset (MIT), structured data derived from the AWS Service Authorization Reference. Not maintained by AWS and not guaranteed current. IAMTrail's managed policy archive is separate.
Definitions bundle generated 4/7/2026, 3:29:24 AM