ec2:DescribeInstances
Literal appearances in AWS managed IAM policies. Statements that use wildcards (for example s3:*) are not counted here. This is not an IAM authorization simulation.
Policies (any)
165
Allow (Action)
165
Deny (Action)
0
NotAction
1
Index generated 4/7/2026, 3:29:24 AM. 559 policies include at least one wildcard action string (any service).
Action reference
SAR-style (unofficial)Service: Amazon EC2
Access level
ListDescription
Grants permission to describe one or more instances
Allow (Action)
- AWS-SSM-DiagnosisAutomation-ExecutionRolePolicy
- AWSApplicationMigrationFullAccess
- AWSApplicationMigrationNetworkMigrationMultiAccount
- AWSApplicationMigrationReadOnlyAccess
- AWSApplicationMigrationReplicationServerPolicy
- AWSApplicationMigrationServiceRolePolicy
- AWSAuditManagerServiceRolePolicy
- AWSBackupFullAccess
- AWSBackupOperatorAccess
- AWSBackupServiceLinkedRolePolicyForBackup
- AWSBackupServiceRolePolicyForBackup
- AWSBackupServiceRolePolicyForRestores
- AWSBatchServiceRole
- AWSBudgetsActionsWithAWSResourceControlAccess
- AWSCloud9ServiceRolePolicy
- AWSCloudFrontVPCOriginServiceRolePolicy
- AWSCloudMapFullAccess
- AWSCloudMapRegisterInstanceAccess
- AWSCodeDeployRole
- AWSConnector
- AWSDataLifecycleManagerServiceRole
- AWSDataLifecycleManagerServiceRoleForAMIManagement
- AWSEC2CapacityReservationFleetRolePolicy
- AWSEC2SpotServiceRolePolicy
- AWSEC2SqlHaServiceRolePolicy
- AWSElasticBeanstalkCustomPlatformforEC2Role
- AWSElasticBeanstalkEnhancedHealth
- AWSElasticBeanstalkManagedUpdatesCustomerRolePolicy
- AWSElasticBeanstalkReadOnly
- AWSElasticBeanstalkService
- AWSElasticBeanstalkServiceRolePolicy
- AWSElasticDisasterRecoveryConsoleFullAccess
- AWSElasticDisasterRecoveryConsoleFullAccess_v2
- AWSElasticDisasterRecoveryCrossAccountReplicationPolicy
- AWSElasticDisasterRecoveryNetworkReplicationPolicy
- AWSElasticDisasterRecoveryReadOnlyAccess
- AWSElasticDisasterRecoveryReplicationServerPolicy
- AWSElasticDisasterRecoveryServiceRolePolicy
- AWSElasticLoadBalancingClassicServiceRolePolicy
- AWSElasticLoadBalancingServiceRolePolicy
- AWSEnhancedClassicNetworkingMangementPolicy
- AWSFaultInjectionSimulatorEC2Access
- AWSFaultInjectionSimulatorECSAccess
- AWSFaultInjectionSimulatorEKSAccess
- AWSGlobalAcceleratorSLRPolicy
- AWSGlueConsoleFullAccess
- AWSGlueConsoleSageMakerNotebookFullAccess
- AWSIoTDeviceTesterForFreeRTOSFullAccess
- AWSLambdaManagedEC2ResourceOperator
- AWSLambdaServiceRolePolicy
- AWSLicenseManagerLinuxSubscriptionsServiceRolePolicy
- AWSLicenseManagerServiceRolePolicy
- AWSLicenseManagerUserSubscriptionsServiceRolePolicy
- AWSMarketplaceFullAccess
- AWSMarketplaceRead-only
- AWSMigrationHubOrchestratorConsoleFullAccess
- AWSMigrationHubOrchestratorServiceRolePolicy
- AWSMigrationHubRefactorSpaces-SSMAutomationPolicy
- AWSNetworkFirewallServiceRolePolicy
- AWSOpsWorksCMServiceRole
- AWSOpsWorksRegisterCLI
- AWSOpsWorksRegisterCLI_EC2
- AWSOpsWorksRegisterCLI_OnPremises
- AWSOpsWorksRole
- AWSOpsWorks_FullAccess
- AWSPCSServiceRolePolicy
- AWSQuickSetupDistributorPermissionsBoundary
- AWSQuickSetupManagedInstanceProfileExecutionPolicy
- AWSQuickSetupPatchPolicyPermissionsBoundary
- AWSQuickSetupSSMHostMgmtPermissionsBoundary
- AWSQuickSetupSchedulerPermissionsBoundary
- AWSQuickSetupStartStopInstancesExecutionPolicy
- AWSReachabilityAnalyzerServiceRolePolicy
- AWSResilienceHubAsssessmentExecutionPolicy
- AWSResourceExplorerServiceRolePolicy
- AWSResourceGroupsReadOnlyAccess
- AWSSSMForSAPServiceLinkedRolePolicy
- AWSServiceRoleForAmazonEKSNodegroup
- AWSServiceRoleForGammaInternalAmazonEKSNodegroup
- AWSServiceRoleForImageBuilder
- AWSServiceRoleForSMS
- AWSServiceRolePolicyForBackupRestoreTesting
- AWSServiceRolePolicyForWorkspacesInstances
- AWSThinkboxAWSPortalAdminPolicy
- AWSThinkboxDeadlineResourceTrackerAccessPolicy
- AWSThinkboxDeadlineSpotEventPluginWorkerPolicy
- AWSTransformApplicationDeploymentPolicy
- AWSTrustedAdvisorServiceRolePolicy
- AWSZonalAutoshiftPracticeRunSLRPolicy
- AmazonApplicationWizardFullaccess
- AmazonDocDBConsoleFullAccess
- AmazonDynamoDBFullAccesswithDataPipeline
- AmazonEBSCSIDriverPolicy
- AmazonEC2ImageReferencesAccessPolicy
- AmazonEC2RolePolicyForApplicationWizard
- AmazonEC2RolePolicyForLaunchWizard
- AmazonECSComputeServiceRolePolicy
- AmazonECSInfrastructureRolePolicyForManagedInstances
- AmazonECSInfrastructureRolePolicyForVolumes
- AmazonECSInfrastructureRolePolicyForVpcLattice
- AmazonEKSClusterPolicy
- AmazonEKSLoadBalancingPolicy
- AmazonEKSLocalOutpostClusterPolicy
- AmazonEKSLocalOutpostServiceRolePolicy
- AmazonEKSServicePolicy
- AmazonEKSServiceRolePolicy
- AmazonEKSWorkerNodePolicy
- AmazonEKS_CNI_Policy
- AmazonEMRCleanupPolicy
- AmazonEMRServicePolicy_v2
- AmazonEVSServiceRolePolicy
- AmazonElasticMapReduceEditorsRole
- AmazonElasticMapReduceFullAccess
- AmazonElasticMapReduceRole
- AmazonFISServiceRolePolicy
- AmazonGrafanaCloudWatchAccess
- AmazonGuardDutyMalwareProtectionServiceRolePolicy
- AmazonGuardDutyServiceRolePolicy
- AmazonInspector2AgentlessServiceRolePolicy
- AmazonInspector2ServiceRolePolicy
- AmazonInspectorFullAccess
- AmazonInspectorReadOnlyAccess
- AmazonInspectorServiceRolePolicy
- AmazonLambdaRolePolicyForLaunchWizardSAP
- AmazonRDSCustomPreviewServiceRolePolicy
- AmazonRDSCustomServiceRolePolicy
- AmazonSSMServiceRolePolicy
- AmazonVPCFullAccess
- AmazonVPCNetworkAccessAnalyzerFullAccessPolicy
- AmazonVPCReachabilityAnalyzerFullAccessPolicy
- AutoScalingConsoleFullAccess
- AutoScalingFullAccess
- BatchServiceRolePolicy
- CloudFrontFullAccess
- CloudWatchApplicationInsightsFullAccess
- CloudWatchAutomaticDashboardsAccess
- CloudWatchEventsServiceRolePolicy
- CloudwatchApplicationInsightsServiceLinkedRolePolicy
- ComputeOptimizerReadOnlyAccess
- ComputeOptimizerServiceRolePolicy
- DBModDiscoveryAndAssessment
- EC2FastLaunchFullAccess
- EC2FastLaunchServiceRolePolicy
- EC2FleetTimeShiftableServiceRolePolicy
- EC2InstanceConnect
- ElasticLoadBalancingFullAccess
- ElasticLoadBalancingReadOnly
- FMSServiceRolePolicy
- GameLiftGameServerGroupPolicy
- GlobalAcceleratorFullAccess
- NeptuneConsoleFullAccess
- NetworkAdministrator
- NetworkSecurityDirectorServiceLinkedRolePolicy
- ROSAAmazonEBSCSIDriverOperatorPolicy
- ROSACloudNetworkConfigOperatorPolicy
- ROSAInstallerPolicy
- ROSAKubeControllerPolicy
- ROSANodePoolManagementPolicy
- ROSASRESupportPolicy
- ROSAWorkerInstancePolicy
- Route53RecoveryReadinessServiceRolePolicy
- SageMakerStudioProjectUserRolePermissionsBoundary
- ServerMigration_ServiceRole
- VPCLatticeFullAccess
- VPCLatticeReadOnlyAccess
Deny (Action)
None
Thanks to Ian McKay for iam-dataset (MIT), structured data derived from the AWS Service Authorization Reference. Not maintained by AWS and not guaranteed current. IAMTrail's managed policy archive is separate.
Definitions bundle generated 4/7/2026, 3:29:24 AM