Amazon S3 adds additional policy details to access denied error messages
Amazon S3 now includes specific AWS Identity and Access Management (IAM) and AWS Organizations policy ARNs in HTTP 403 Access Denied error messages. This allows users to identify the exact policy responsible for a denied request.
Why it matters
Developers can resolve permission issues faster because they no longer need to manually inspect multiple policies to find the root cause of an access denial.
The details
- Applies to same-account and same-organization requests for explicit deny cases.
- Covers Service Control Policies, Resource Control Policies, identity-based policies, session policies, and permission boundaries.
- Available in all AWS Regions, including GovCloud (US) and China Regions.
Show entities and relationshipsHide entities and relationships
In this article
Key connections
AWS owns AWS Organizations
AWS develops and operates AWS Organizations
Amazon S3 includes IAM policy ARNs in access denied error messages
Amazon S3 uses AWS Organizations
Amazon S3 includes AWS Organizations policy ARNs in access denied error messages
Amazon S3 uses Amazon Resource Name (ARN)
Amazon S3 includes specific policy ARNs in HTTP 403 Access Denied error messages
AWS Organizations uses Service Control Policies (SCPs)
AWS Organizations uses Service Control Policies (SCPs) to manage organization-wide permissions
AWS Organizations uses Resource Control Policies (RCPs)
AWS Organizations uses Resource Control Policies (RCPs) to enforce resource perimeter controls
Show 4 more connectionsShow fewer connections
Related events
Amazon S3 Adds Policy Details to Access Denied Error Messages
Get the weekly recap
The stories like this one, picked and explained — once a week, straight to your inbox.