iam:GetRolePolicy
Literal appearances in AWS managed IAM policies. Statements that use wildcards (for example s3:*) are not counted here. This is not an IAM authorization simulation.
Policies (any)
60
Allow (Action)
60
Deny (Action)
0
NotAction
3
Index generated 4/7/2026, 3:29:24 AM. 559 policies include at least one wildcard action string (any service).
Action reference
SAR-style (unofficial)Service: AWS Identity and Access Management (IAM)
Access level
ReadDescription
Grants permission to retrieve an inline policy document that is embedded with the specified IAM role
Resource types
- role*
Allow (Action)
- AIDevOpsAgentAccessPolicy
- AIOpsAssistantPolicy
- AWSApplicationMigrationNetworkMigrationMultiAccount
- AWSAuditManagerServiceRolePolicy
- AWSCloudTrailFullAccess
- AWSCloudTrail_FullAccess
- AWSCodeStarServiceRole
- AWSConfigRole
- AWSConfigServiceRolePolicy
- AWSControlTowerServiceRolePolicy
- AWSDataPipelineRole
- AWSDataPipeline_FullAccess
- AWSDataPipeline_PowerUser
- AWSGlueConsoleFullAccess
- AWSGlueConsoleSageMakerNotebookFullAccess
- AWSGlueServiceRole
- AWSIoTDeviceDefenderAudit
- AWSLakeFormationDataAdmin
- AWSLambdaFullAccess
- AWSLambdaReadOnlyAccess
- AWSLambda_FullAccess
- AWSLambda_ReadOnlyAccess
- AWSOpsWorksFullAccess
- AWSOpsWorksRole
- AWSOpsWorks_FullAccess
- AWSQuickSetupDeploymentRolePolicy
- AWSQuickSetupDistributorPermissionsBoundary
- AWSQuickSetupJITNADeploymentRolePolicy
- AWSQuickSetupPatchPolicyDeploymentRolePolicy
- AWSQuickSetupPatchPolicyPermissionsBoundary
- AWSQuickSetupSSMDeploymentRolePolicy
- AWSQuickSetupSSMHostMgmtPermissionsBoundary
- AWSQuickSetupSSMManageResourcesExecutionPolicy
- AWSResourceExplorerServiceRolePolicy
- AWSThinkboxAWSPortalAdminPolicy
- AWSTransformApplicationDeploymentPolicy
- AWSTransformApplicationECSDeploymentPolicy
- AWS_ConfigRole
- AWS_Config_Role
- AccessAnalyzerServiceRolePolicy
- AdministratorAccess-Amplify
- AmazonApplicationWizardFullaccess
- AmazonBraketFullAccess
- AmazonDataZoneEnvironmentRolePermissionsBoundary
- AmazonDataZoneProjectDeploymentPermissionsBoundary
- AmazonDataZoneProjectRolePermissionsBoundary
- AmazonDataZoneSageMakerProvisioningRolePolicy
- AmazonDynamoDBFullAccesswithDataPipeline
- AmazonEKSMCPReadOnlyAccess
- AmazonElasticMapReduceRole
- AmazonInspector2ServiceRolePolicy
- AmazonLaunchWizardFullAccessV2
- AmazonLaunchWizardFullaccess
- AmazonLaunchWizard_Fullaccess
- AmazonRDSCustomPreviewServiceRolePolicy
- AmazonRDSCustomServiceRolePolicy
- AmazonSecurityLakeAdministrator
- BedrockAgentCoreFullAccess
- DBModDiscoveryAndAssessment
- SageMakerStudioProjectProvisioningRolePolicy
Deny (Action)
Thanks to Ian McKay for iam-dataset (MIT), structured data derived from the AWS Service Authorization Reference. Not maintained by AWS and not guaranteed current. IAMTrail's managed policy archive is separate.
Definitions bundle generated 4/7/2026, 3:29:24 AM