Policy: AmazonSSMFullAccess ARN: arn:aws:iam::aws:policy/AmazonSSMFullAccess Allowed Actions Actions Services cloudwatch:PutMetricData cloudwatch ds:CreateComputer ds ds:DescribeDirectories ds ec2:DescribeInstanceStatus ec2 ec2messages:* ec2messages iam:CreateServiceLinkedRole iam iam:DeleteServiceLinkedRole iam iam:GetServiceLinkedRoleDeletionStatus iam logs:* logs ssm:* ssm ssmmessages:CreateControlChannel ssmmessages ssmmessages:CreateDataChannel ssmmessages ssmmessages:OpenControlChannel ssmmessages ssmmessages:OpenDataChannel ssmmessages