ec2:DescribeSecurityGroups
Literal appearances in AWS managed IAM policies. Statements that use wildcards (for example s3:*) are not counted here. This is not an IAM authorization simulation.
Policies (any)
226
Allow (Action)
226
Deny (Action)
0
NotAction
2
Index generated 4/7/2026, 3:29:24 AM. 559 policies include at least one wildcard action string (any service).
Action reference
SAR-style (unofficial)Service: Amazon EC2
Access level
ListDescription
Grants permission to describe one or more security groups
Allow (Action)
- APIGatewayServiceRolePolicy
- AWS-SSM-DiagnosisAutomation-ExecutionRolePolicy
- AWS-SSM-RemediationAutomation-ExecutionRolePolicy
- AWSApplicationMigrationFullAccess
- AWSApplicationMigrationNetworkMigrationMultiAccount
- AWSApplicationMigrationReadOnlyAccess
- AWSApplicationMigrationServiceRolePolicy
- AWSAuditManagerServiceRolePolicy
- AWSB9InternalServicePolicy
- AWSBackupFullAccess
- AWSBackupOperatorAccess
- AWSBackupServiceRolePolicyForRestores
- AWSBatchFullAccess
- AWSBatchServiceRole
- AWSBedrockAgentCoreGatewayNetworkServiceRolePolicy
- AWSCloud9ServiceRolePolicy
- AWSCloudFrontVPCOriginServiceRolePolicy
- AWSCodeBuildAdminAccess
- AWSCodePipeline_FullAccess
- AWSDataSyncFullAccess
- AWSDataSyncReadOnlyAccess
- AWSDeepRacerCloudFormationAccessPolicy
- AWSDeepRacerRoboMakerAccessPolicy
- AWSDeviceFarmServiceRolePolicy
- AWSDeviceFarmTestGridServiceRolePolicy
- AWSDirectoryServiceFullAccess
- AWSDirectoryServiceServiceRolePolicy
- AWSElasticBeanstalkCustomPlatformforEC2Role
- AWSElasticBeanstalkEnhancedHealth
- AWSElasticBeanstalkManagedUpdatesCustomerRolePolicy
- AWSElasticBeanstalkReadOnly
- AWSElasticBeanstalkService
- AWSElasticBeanstalkServiceRolePolicy
- AWSElasticDisasterRecoveryConsoleFullAccess
- AWSElasticDisasterRecoveryConsoleFullAccess_v2
- AWSElasticDisasterRecoveryNetworkReplicationPolicy
- AWSElasticDisasterRecoveryReadOnlyAccess
- AWSElasticDisasterRecoveryServiceRolePolicy
- AWSElasticLoadBalancingClassicServiceRolePolicy
- AWSElasticLoadBalancingServiceRolePolicy
- AWSEnhancedClassicNetworkingMangementPolicy
- AWSGlobalAcceleratorSLRPolicy
- AWSGlueConsoleFullAccess
- AWSGlueConsoleSageMakerNotebookFullAccess
- AWSGlueDataBrewServiceRole
- AWSGlueServiceRole
- AWSHealthOmicsServiceLinkedRolePolicy
- AWSIPAMServiceRolePolicy
- AWSImageBuilderFullAccess
- AWSIoTDeviceTesterForFreeRTOSFullAccess
- AWSKeyManagementServiceCustomKeyStoresServiceRolePolicy
- AWSLambdaFullAccess
- AWSLambdaMSKExecutionRole
- AWSLambdaManagedEC2ResourceOperator
- AWSLambdaReadOnlyAccess
- AWSLambda_FullAccess
- AWSLambda_ReadOnlyAccess
- AWSMarketplaceFullAccess
- AWSMarketplaceImageBuildFullAccess
- AWSMarketplaceRead-only
- AWSMediaConnectServicePolicy
- AWSMigrationHubRefactorSpacesFullAccess
- AWSMigrationHubRefactorSpacesServiceRolePolicy
- AWSMobileHub_FullAccess
- AWSOpsWorksCMServiceRole
- AWSOpsWorksFullAccess
- AWSOpsWorksRole
- AWSOpsWorks_FullAccess
- AWSOutpostsServiceRolePolicy
- AWSPCSServiceRolePolicy
- AWSReachabilityAnalyzerServiceRolePolicy
- AWSRefactoringToolkitFullAccess
- AWSResourceExplorerServiceRolePolicy
- AWSResourceGroupsReadOnlyAccess
- AWSRoboMakerServicePolicy
- AWSRoboMakerServiceRolePolicy
- AWSS3OnOutpostsServiceRolePolicy
- AWSServiceRoleForAIDevOpsPolicy
- AWSServiceRoleForAmazonEKSNodegroup
- AWSServiceRoleForGammaInternalAmazonEKSNodegroup
- AWSThinkboxAWSPortalAdminPolicy
- AWSTransferConsoleFullAccess
- AWSTransformApplicationDeploymentPolicy
- AWSTransformApplicationECSDeploymentPolicy
- AWSTrustedAdvisorServiceRolePolicy
- AWSVpcLatticeServiceRolePolicy
- AmazonAppStreamFullAccess
- AmazonAppStreamServiceAccess
- AmazonApplicationWizardFullaccess
- AmazonBedrockFullAccess
- AmazonBedrockLimitedAccess
- AmazonDMSVPCManagementRole
- AmazonDRSVPCManagement
- AmazonDataZoneFullAccess
- AmazonDataZoneGlueManageAccessRolePolicy
- AmazonDataZoneSageMakerEnvironmentRolePermissionsBoundary
- AmazonDocDBConsoleFullAccess
- AmazonDocDBElasticFullAccess
- AmazonDocDBFullAccess
- AmazonDocDBReadOnlyAccess
- AmazonDynamoDBFullAccess
- AmazonDynamoDBFullAccess_v2
- AmazonDynamoDBReadOnlyAccess
- AmazonECSInfrastructureRolePolicyForManagedInstances
- AmazonECSInfrastructureRoleforExpressGatewayServices
- AmazonEKSClusterPolicy
- AmazonEKSForFargateServiceRolePolicy
- AmazonEKSLoadBalancingPolicy
- AmazonEKSLocalOutpostServiceRolePolicy
- AmazonEKSServicePolicy
- AmazonEKSServiceRolePolicy
- AmazonEKSWorkerNodePolicy
- AmazonEKS_CNI_Policy
- AmazonEMRContainersServiceRolePolicy
- AmazonEMRFullAccessPolicy_v2
- AmazonEMRServerlessServiceRolePolicy
- AmazonEMRServicePolicy_v2
- AmazonElastiCacheFullAccess
- AmazonElasticFileSystemFullAccess
- AmazonElasticFileSystemReadOnlyAccess
- AmazonElasticFileSystemServiceRolePolicy
- AmazonElasticMapReduceEditorsRole
- AmazonElasticMapReduceFullAccess
- AmazonElasticMapReduceRole
- AmazonElasticsearchServiceRolePolicy
- AmazonFSxConsoleFullAccess
- AmazonFSxConsoleReadOnlyAccess
- AmazonFSxFullAccess
- AmazonFSxServiceRolePolicy
- AmazonGrafanaServiceLinkedRolePolicy
- AmazonGuardDutyServiceRolePolicy
- AmazonInspector2ServiceRolePolicy
- AmazonInspectorServiceRolePolicy
- AmazonKendraFullAccess
- AmazonMQApiFullAccess
- AmazonMQApiReadOnlyAccess
- AmazonMQFullAccess
- AmazonMQReadOnlyAccess
- AmazonMSKFullAccess
- AmazonMSKReadOnlyAccess
- AmazonMWAAServerlessServiceRolePolicy
- AmazonMWAAServiceRolePolicy
- AmazonMachineLearningRoleforRedshiftDataSource
- AmazonMachineLearningRoleforRedshiftDataSourceV2
- AmazonMachineLearningRoleforRedshiftDataSourceV3
- AmazonManagedBlockchainConsoleFullAccess
- AmazonNimbleStudio-LaunchProfileWorker
- AmazonNimbleStudio-StudioAdmin
- AmazonNimbleStudio-StudioUser
- AmazonOpenSearchIngestionServiceRolePolicy
- AmazonOpenSearchServiceRolePolicy
- AmazonPrometheusFullAccess
- AmazonPrometheusScraperServiceRolePolicy
- AmazonRDSBetaServiceRolePolicy
- AmazonRDSCustomPreviewServiceRolePolicy
- AmazonRDSCustomServiceRolePolicy
- AmazonRDSFullAccess
- AmazonRDSPreviewServiceRolePolicy
- AmazonRDSReadOnlyAccess
- AmazonRDSServiceRolePolicy
- AmazonRedshiftFullAccess
- AmazonRedshiftReadOnlyAccess
- AmazonRedshiftServiceLinkedRolePolicy
- AmazonRoute53ResolverFullAccess
- AmazonRoute53ResolverReadOnlyAccess
- AmazonS3OutpostsFullAccess
- AmazonS3OutpostsReadOnlyAccess
- AmazonSageMakerCanvasFullAccess
- AmazonSageMakerCoreServiceRolePolicy
- AmazonSageMakerFullAccess
- AmazonSageMakerHyperPodInferenceAccess
- AmazonSageMakerNotebooksServiceRolePolicy
- AmazonSageMakerQuickSightVPCPolicy
- AmazonTimestreamInfluxDBFullAccess
- AmazonTimestreamInfluxDBFullAccessWithoutMarketplaceAccess
- AmazonVPCFullAccess
- AmazonVPCNetworkAccessAnalyzerFullAccessPolicy
- AmazonVPCReachabilityAnalyzerFullAccessPolicy
- AmazonVPCReadOnlyAccess
- AmazonWorkSpacesPoolServiceAccess
- AmazonWorkSpacesSecureBrowserReadOnly
- AmazonWorkSpacesWebReadOnly
- AmazonWorkSpacesWebServiceRolePolicy
- AppRunnerNetworkingServiceRolePolicy
- AutoScalingConsoleFullAccess
- AutoScalingFullAccess
- AwsGlueDataBrewFullAccessPolicy
- BatchServiceRolePolicy
- BedrockAgentCoreNetworkServiceRolePolicy
- ClientVPNServiceRolePolicy
- CloudWatchNetworkMonitorServiceRolePolicy
- CloudWatchSyntheticsFullAccess
- DAXServiceRolePolicy
- DBModDiscoveryAndAssessment
- DatabaseAdministrator
- EC2FastLaunchFullAccess
- ElastiCacheServiceRolePolicy
- ElasticLoadBalancingFullAccess
- ElasticLoadBalancingReadOnly
- FMSServiceRolePolicy
- MemoryDBServiceRolePolicy
- NeptuneConsoleFullAccess
- NeptuneFullAccess
- NeptuneGraphReadOnlyAccess
- NeptuneReadOnlyAccess
- NetworkAdministrator
- NetworkSecurityDirectorServiceLinkedRolePolicy
- OpensearchIngestionSelfManagedVpcePolicy
- ROSAControlPlaneOperatorPolicy
- ROSAInstallerPolicy
- ROSAKubeControllerPolicy
- ROSANodePoolManagementPolicy
- ROSASRESupportPolicy
- ROSASharedVPCEndpointPolicy
- RTBFabricServiceRolePolicy
- SageMakerStudioAdminIAMConsolePolicy
- SageMakerStudioFullAccess
- SageMakerStudioProjectProvisioningRolePolicy
- SageMakerStudioProjectRoleMachineLearningPolicy
- SageMakerStudioProjectUserRolePermissionsBoundary
- SageMakerStudioProjectUserRolePolicy
- SecretsManagerReadWrite
- ServerMigrationServiceConsoleFullAccess
- VPCLatticeFullAccess
- VPCLatticeReadOnlyAccess
- ViewOnlyAccess
Deny (Action)
None
Thanks to Ian McKay for iam-dataset (MIT), structured data derived from the AWS Service Authorization Reference. Not maintained by AWS and not guaranteed current. IAMTrail's managed policy archive is separate.
Definitions bundle generated 4/7/2026, 3:29:24 AM