kms:CreateGrant
Literal appearances in AWS managed IAM policies. Statements that use wildcards (for example s3:*) are not counted here. This is not an IAM authorization simulation.
Policies (any)
47
Allow (Action)
46
Deny (Action)
1
NotAction
1
571 policies include at least one wildcard action string (any service). Index regenerated on every deploy.
First seen
From archive historyThis action
Already present when the archive began, on 2019-02-10
Earliest appearance in any AWS managed policy tracked here, not an official AWS launch date. Matched case-insensitively, as IAM does.
Action reference
SAR-style (unofficial)Service: AWS Key Management Service
Access level
Permissions management, WriteDescription
Controls permission to add a grant to an AWS KMS key. You can use grants to add permissions without changing the key policy or IAM policy
Resource types
- key*
Allow (Action)
- AWSAuditManagerAdministratorAccess
- AWSBackupAdminPolicy
- AWSBackupFullAccess
- AWSBackupGuardDutyRolePolicyForScans
- AWSBackupOperatorPolicy
- AWSBackupServiceLinkedRolePolicyForBackup
- AWSBackupServiceRolePolicyForBackup
- AWSBackupServiceRolePolicyForRestores
- AWSFaultInjectionSimulatorEC2Access
- AWSProtonFullAccess
- AWSRefactoringToolkitFullAccess
- AWSServiceRoleForImageBuilder
- AWSSupplyChainFederationAdminAccess
- AWSSystemsManagerJustInTimeAccessTokenPolicy
- AWSSystemsManagerJustInTimeAccessTokenSessionPolicy
- AWSTransformApplicationDeploymentPolicy
- AWSTransformApplicationECSDeploymentPolicy
- AmazonAppFlowFullAccess
- AmazonConnectFullAccess
- AmazonDataZoneSageMakerManageAccessRolePolicy
- AmazonDocDBElasticFullAccess
- AmazonGuardDutyMalwareProtectionServiceRolePolicy
- AmazonLookoutEquipmentFullAccess
- AmazonMSKFullAccess
- AmazonMonitronFullAccess
- AmazonSageMakerModelRegistryFullAccess
- AmazonSecurityLakeAdministrator
- AmazonTimestreamConsoleFullAccess
- AmazonTimestreamFullAccess
- BedrockAgentCoreFullAccess
- EC2ImageBuilderExecutionPolicy
- ROSAAmazonEBSCSIDriverOperatorPolicy
- ROSAInstallerPolicy
- ROSAKarpenterControllerPolicy
- ROSANodePoolManagementPolicy
- SageMakerStudioAdminIAMConsolePolicy
- SageMakerStudioAdminIAMDefaultExecutionPolicy
- SageMakerStudioAdminIAMPermissiveExecutionPolicy
- SageMakerStudioEMRInstanceRolePolicy
- SageMakerStudioEMRServiceRolePolicy
- SageMakerStudioProjectProvisioningRolePolicy
- SageMakerStudioProjectRoleMachineLearningPolicy
- SageMakerStudioProjectUserRolePermissionsBoundary
- SageMakerStudioProjectUserRolePolicy
- SageMakerStudioUserIAMDefaultExecutionPolicy
- SageMakerStudioUserIAMPermissiveExecutionPolicy
Deny (Action)
Thanks to Ian McKay for iam-dataset (MIT), structured data derived from the AWS Service Authorization Reference. Not maintained by AWS and not guaranteed current. IAMTrail's managed policy archive is separate.
Definitions bundle regenerated on every deploy