ec2:DescribeVpcs
Literal appearances in AWS managed IAM policies. Statements that use wildcards (for example s3:*) are not counted here. This is not an IAM authorization simulation.
Policies (any)
215
Allow (Action)
215
Deny (Action)
0
NotAction
2
Index generated 4/7/2026, 3:29:24 AM. 559 policies include at least one wildcard action string (any service).
Action reference
SAR-style (unofficial)Service: Amazon EC2
Access level
ListDescription
Grants permission to describe one or more VPCs
Allow (Action)
- APIGatewayServiceRolePolicy
- AWS-SSM-DiagnosisAutomation-ExecutionRolePolicy
- AWS-SSM-RemediationAutomation-ExecutionRolePolicy
- AWSApplicationMigrationNetworkMigrationMultiAccount
- AWSAuditManagerServiceRolePolicy
- AWSB9InternalServicePolicy
- AWSBackupFullAccess
- AWSBackupOperatorAccess
- AWSBackupServiceRolePolicyForRestores
- AWSBatchFullAccess
- AWSBedrockAgentCoreGatewayNetworkServiceRolePolicy
- AWSCloud9Administrator
- AWSCloud9ServiceRolePolicy
- AWSCloud9User
- AWSCloudHSMRole
- AWSCloudMapFullAccess
- AWSCodeBuildAdminAccess
- AWSCodePipeline_FullAccess
- AWSCodeStarFullAccess
- AWSDeepRacerCloudFormationAccessPolicy
- AWSDeepRacerRoboMakerAccessPolicy
- AWSDeviceFarmServiceRolePolicy
- AWSDeviceFarmTestGridServiceRolePolicy
- AWSDirectoryServiceFullAccess
- AWSDirectoryServiceReadOnlyAccess
- AWSDirectoryServiceServiceRolePolicy
- AWSElasticBeanstalkManagedUpdatesCustomerRolePolicy
- AWSElasticBeanstalkReadOnly
- AWSElasticBeanstalkService
- AWSElasticDisasterRecoveryNetworkReplicationPolicy
- AWSElasticDisasterRecoveryServiceRolePolicy
- AWSElasticLoadBalancingClassicServiceRolePolicy
- AWSElasticLoadBalancingServiceRolePolicy
- AWSFaultInjectionSimulatorNetworkAccess
- AWSGlueConsoleFullAccess
- AWSGlueConsoleSageMakerNotebookFullAccess
- AWSHealthOmicsServiceLinkedRolePolicy
- AWSIPAMServiceRolePolicy
- AWSImageBuilderFullAccess
- AWSKeyManagementServiceCustomKeyStoresServiceRolePolicy
- AWSLambdaFullAccess
- AWSLambdaMSKExecutionRole
- AWSLambdaReadOnlyAccess
- AWSLambda_FullAccess
- AWSLambda_ReadOnlyAccess
- AWSMarketplaceFullAccess
- AWSMarketplaceRead-only
- AWSMigrationHubOrchestratorConsoleFullAccess
- AWSMigrationHubRefactorSpaces-EnvironmentsWithoutBridgesFullAccess
- AWSMigrationHubRefactorSpacesFullAccess
- AWSMobileHub_FullAccess
- AWSNetworkFirewallFullAccess
- AWSNetworkFirewallServiceRolePolicy
- AWSNetworkManagerServiceRolePolicy
- AWSObservabilityAdminTelemetryEnablementServiceRolePolicy
- AWSOpsWorksFullAccess
- AWSOpsWorksRole
- AWSOpsWorks_FullAccess
- AWSPCSServiceRolePolicy
- AWSReachabilityAnalyzerServiceRolePolicy
- AWSRefactoringToolkitFullAccess
- AWSResourceExplorerServiceRolePolicy
- AWSResourceGroupsReadOnlyAccess
- AWSRoboMakerServicePolicy
- AWSRoboMakerServiceRolePolicy
- AWSS3OnOutpostsServiceRolePolicy
- AWSSSMForSAPServiceLinkedRolePolicy
- AWSServiceRoleForAIDevOpsPolicy
- AWSThinkboxAWSPortalAdminPolicy
- AWSTransferConsoleFullAccess
- AWSTransformApplicationDeploymentPolicy
- AWSTrustedAdvisorServiceRolePolicy
- AWSVpcLatticeServiceRolePolicy
- AccessAnalyzerServiceRolePolicy
- AmazonAppStreamFullAccess
- AmazonAppStreamServiceAccess
- AmazonBedrockFullAccess
- AmazonBedrockLimitedAccess
- AmazonDMSVPCManagementRole
- AmazonDRSVPCManagement
- AmazonDataZoneFullAccess
- AmazonDataZoneSageMakerEnvironmentRolePermissionsBoundary
- AmazonDataZoneSageMakerProvisioningRolePolicy
- AmazonDocDBConsoleFullAccess
- AmazonDocDBElasticFullAccess
- AmazonDocDBFullAccess
- AmazonDocDBReadOnlyAccess
- AmazonDynamoDBFullAccess
- AmazonDynamoDBFullAccess_v2
- AmazonDynamoDBReadOnlyAccess
- AmazonECSInfrastructureRolePolicyForManagedInstances
- AmazonECSInfrastructureRolePolicyForVpcLattice
- AmazonECSInfrastructureRoleforExpressGatewayServices
- AmazonEKSClusterPolicy
- AmazonEKSForFargateServiceRolePolicy
- AmazonEKSLoadBalancingPolicy
- AmazonEKSLocalOutpostServiceRolePolicy
- AmazonEKSMCPReadOnlyAccess
- AmazonEKSServicePolicy
- AmazonEKSServiceRolePolicy
- AmazonEKSWorkerNodePolicy
- AmazonEMRFullAccessPolicy_v2
- AmazonEMRServerlessServiceRolePolicy
- AmazonEMRServicePolicy_v2
- AmazonEVSServiceRolePolicy
- AmazonElastiCacheFullAccess
- AmazonElasticFileSystemFullAccess
- AmazonElasticFileSystemReadOnlyAccess
- AmazonElasticMapReduceEditorsRole
- AmazonElasticMapReduceFullAccess
- AmazonElasticMapReduceRole
- AmazonElasticsearchServiceRolePolicy
- AmazonFSxConsoleFullAccess
- AmazonFSxConsoleReadOnlyAccess
- AmazonFSxFullAccess
- AmazonFSxServiceRolePolicy
- AmazonGrafanaServiceLinkedRolePolicy
- AmazonGuardDutyServiceRolePolicy
- AmazonInspector2ServiceRolePolicy
- AmazonInspectorServiceRolePolicy
- AmazonKendraFullAccess
- AmazonLambdaRolePolicyForLaunchWizardSAP
- AmazonMQApiFullAccess
- AmazonMQApiReadOnlyAccess
- AmazonMQFullAccess
- AmazonMQReadOnlyAccess
- AmazonMSKFullAccess
- AmazonMSKReadOnlyAccess
- AmazonMWAAServerlessServiceRolePolicy
- AmazonMWAAServiceRolePolicy
- AmazonManagedBlockchainConsoleFullAccess
- AmazonOpenSearchServiceRolePolicy
- AmazonRDSBetaServiceRolePolicy
- AmazonRDSCustomPreviewServiceRolePolicy
- AmazonRDSCustomServiceRolePolicy
- AmazonRDSFullAccess
- AmazonRDSPreviewServiceRolePolicy
- AmazonRDSReadOnlyAccess
- AmazonRDSServiceRolePolicy
- AmazonRedshiftFullAccess
- AmazonRedshiftReadOnlyAccess
- AmazonRedshiftServiceLinkedRolePolicy
- AmazonRoute53AutoNamingFullAccess
- AmazonRoute53FullAccess
- AmazonRoute53ProfilesFullAccess
- AmazonRoute53ResolverFullAccess
- AmazonRoute53ResolverReadOnlyAccess
- AmazonS3OutpostsFullAccess
- AmazonS3OutpostsReadOnlyAccess
- AmazonSageMakerCanvasFullAccess
- AmazonSageMakerCoreServiceRolePolicy
- AmazonSageMakerFullAccess
- AmazonSageMakerHyperPodInferenceAccess
- AmazonSageMakerNotebooksServiceRolePolicy
- AmazonSageMakerQuickSightVPCPolicy
- AmazonTimestreamInfluxDBFullAccess
- AmazonTimestreamInfluxDBFullAccessWithoutMarketplaceAccess
- AmazonTimestreamInfluxDBServiceRolePolicy
- AmazonVPCCrossAccountNetworkInterfaceOperations
- AmazonVPCFullAccess
- AmazonVPCNetworkAccessAnalyzerFullAccessPolicy
- AmazonVPCReachabilityAnalyzerFullAccessPolicy
- AmazonVPCReadOnlyAccess
- AmazonWorkDocsFullAccess
- AmazonWorkDocsReadOnlyAccess
- AmazonWorkMailFullAccess
- AmazonWorkSpacesPoolServiceAccess
- AmazonWorkSpacesSecureBrowserReadOnly
- AmazonWorkSpacesWebReadOnly
- AmazonWorkSpacesWebServiceRolePolicy
- AmazonZocaloFullAccess
- AmazonZocaloReadOnlyAccess
- AppRunnerNetworkingServiceRolePolicy
- AutoScalingConsoleFullAccess
- AutoScalingConsoleReadOnlyAccess
- AwsGlueDataBrewFullAccessPolicy
- BedrockAgentCoreNetworkServiceRolePolicy
- ClientVPNServiceRolePolicy
- CloudWatchInternetMonitorFullAccess
- CloudWatchInternetMonitorServiceRolePolicy
- CloudWatchNetworkMonitorServiceRolePolicy
- CloudWatchSyntheticsFullAccess
- CloudwatchApplicationInsightsServiceLinkedRolePolicy
- DAXServiceRolePolicy
- DBModDiscoveryAndAssessment
- DatabaseAdministrator
- EC2FastLaunchFullAccess
- ElastiCacheServiceRolePolicy
- ElasticLoadBalancingFullAccess
- FMSServiceRolePolicy
- MemoryDBServiceRolePolicy
- NeptuneConsoleFullAccess
- NeptuneFullAccess
- NeptuneGraphReadOnlyAccess
- NeptuneReadOnlyAccess
- NetworkAdministrator
- NetworkSecurityDirectorServiceLinkedRolePolicy
- ROSAControlPlaneOperatorPolicy
- ROSAInstallerPolicy
- ROSAKubeControllerPolicy
- ROSANodePoolManagementPolicy
- ROSASharedVPCEndpointPolicy
- RTBFabricServiceRolePolicy
- Route53RecoveryReadinessServiceRolePolicy
- SageMakerStudioAdminIAMConsolePolicy
- SageMakerStudioFullAccess
- SageMakerStudioProjectProvisioningRolePolicy
- SageMakerStudioProjectRoleMachineLearningPolicy
- SageMakerStudioProjectUserRolePermissionsBoundary
- SageMakerStudioProjectUserRolePolicy
- SecretsManagerReadWrite
- SecurityLakeServiceLinkedRole
- ServerMigrationServiceConsoleFullAccess
- VPCLatticeFullAccess
- VPCLatticeReadOnlyAccess
Deny (Action)
None
Thanks to Ian McKay for iam-dataset (MIT), structured data derived from the AWS Service Authorization Reference. Not maintained by AWS and not guaranteed current. IAMTrail's managed policy archive is separate.
Definitions bundle generated 4/7/2026, 3:29:24 AM