Policy: AmazonElasticMapReduceFullAccess ARN: arn:aws:iam::aws:policy/AmazonElasticMapReduceFullAccess Allowed Actions Actions Services cloudformation:CreateStack cloudformation cloudformation:DescribeStackEvents cloudformation cloudwatch:* cloudwatch ec2:AuthorizeSecurityGroupEgress ec2 ec2:AuthorizeSecurityGroupIngress ec2 ec2:CancelSpotInstanceRequests ec2 ec2:CreateRoute ec2 ec2:CreateSecurityGroup ec2 ec2:CreateTags ec2 ec2:CreateVpcEndpoint ec2 ec2:DeleteRoute ec2 ec2:DeleteSecurityGroup ec2 ec2:DeleteTags ec2 ec2:DescribeAccountAttributes ec2 ec2:DescribeAvailabilityZones ec2 ec2:DescribeInstances ec2 ec2:DescribeKeyPairs ec2 ec2:DescribeNetworkAcls ec2 ec2:DescribeRouteTables ec2 ec2:DescribeRouteTables ec2 ec2:DescribeSecurityGroups ec2 ec2:DescribeSpotInstanceRequests ec2 ec2:DescribeSpotPriceHistory ec2 ec2:DescribeSubnets ec2 ec2:DescribeVpcAttribute ec2 ec2:DescribeVpcs ec2 ec2:ModifyImageAttribute ec2 ec2:ModifyInstanceAttribute ec2 ec2:RequestSpotInstances ec2 ec2:RevokeSecurityGroupEgress ec2 ec2:RunInstances ec2 ec2:TerminateInstances ec2 elasticmapreduce:* elasticmapreduce iam:CreateServiceLinkedRole iam iam:GetPolicy iam iam:GetPolicyVersion iam iam:ListRoles iam iam:PassRole iam kms:List* kms s3:* s3 sdb:* sdb