Skip to content

Policy: AWSAuditManagerServiceRolePolicy

ARN: arn:aws:iam::aws:policy/aws-service-role/AWSAuditManagerServiceRolePolicy

Allowed Actions

Actions Services
acm:GetAccountConfiguration acm
acm:ListCertificates acm
apigateway:GET apigateway
autoscaling:DescribeAutoScalingGroups autoscaling
backup:ListBackupPlans backup
backup:ListRecoveryPointsByResource backup
bedrock:GetCustomModel bedrock
bedrock:GetFoundationModel bedrock
bedrock:GetModelCustomizationJob bedrock
bedrock:GetModelInvocationLoggingConfiguration bedrock
bedrock:ListCustomModels bedrock
bedrock:ListFoundationModels bedrock
bedrock:ListGuardrails bedrock
bedrock:ListModelCustomizationJobs bedrock
cloudfront:GetDistribution cloudfront
cloudfront:GetDistributionConfig cloudfront
cloudfront:ListDistributions cloudfront
cloudtrail:DescribeTrails cloudtrail
cloudtrail:GetTrail cloudtrail
cloudtrail:ListTrails cloudtrail
cloudtrail:LookupEvents cloudtrail
cloudwatch:DescribeAlarms cloudwatch
cloudwatch:DescribeAlarmsForMetric cloudwatch
cloudwatch:GetMetricStatistics cloudwatch
cloudwatch:ListMetrics cloudwatch
cognito-idp:DescribeUserPool cognito-idp
config:DescribeConfigRules config
config:DescribeDeliveryChannels config
config:ListDiscoveredResources config
directconnect:DescribeDirectConnectGateways directconnect
directconnect:DescribeVirtualGateways directconnect
dynamodb:DescribeBackup dynamodb
dynamodb:DescribeContinuousBackups dynamodb
dynamodb:DescribeTable dynamodb
dynamodb:DescribeTableReplicaAutoScaling dynamodb
dynamodb:ListBackups dynamodb
dynamodb:ListGlobalTables dynamodb
dynamodb:ListTables dynamodb
ec2:DescribeAddresses ec2
ec2:DescribeCustomerGateways ec2
ec2:DescribeEgressOnlyInternetGateways ec2
ec2:DescribeFlowLogs ec2
ec2:DescribeInstanceAttribute ec2
ec2:DescribeInstanceCreditSpecifications ec2
ec2:DescribeInstances ec2
ec2:DescribeInternetGateways ec2
ec2:DescribeLocalGatewayRouteTableVirtualInterfaceGroupAssociations ec2
ec2:DescribeLocalGatewayVirtualInterfaces ec2
ec2:DescribeLocalGateways ec2
ec2:DescribeNatGateways ec2
ec2:DescribeNetworkAcls ec2
ec2:DescribeRouteTables ec2
ec2:DescribeSecurityGroupRules ec2
ec2:DescribeSecurityGroups ec2
ec2:DescribeSnapshots ec2
ec2:DescribeTransitGateways ec2
ec2:DescribeVolumes ec2
ec2:DescribeVpcEndpointConnections ec2
ec2:DescribeVpcEndpointServiceConfigurations ec2
ec2:DescribeVpcEndpoints ec2
ec2:DescribeVpcPeeringConnections ec2
ec2:DescribeVpcs ec2
ec2:DescribeVpnConnections ec2
ec2:DescribeVpnGateways ec2
ec2:GetEbsDefaultKmsKeyId ec2
ec2:GetEbsEncryptionByDefault ec2
ec2:GetLaunchTemplateData ec2
ecs:DescribeClusters ecs
eks:DescribeAddonVersions eks
elasticache:DescribeCacheClusters elasticache
elasticache:DescribeServiceUpdates elasticache
elasticfilesystem:DescribeAccessPoints elasticfilesystem
elasticfilesystem:DescribeFileSystems elasticfilesystem
elasticloadbalancing:DescribeLoadBalancers elasticloadbalancing
elasticloadbalancing:DescribeSslPolicies elasticloadbalancing
elasticloadbalancing:DescribeTargetGroups elasticloadbalancing
elasticmapreduce:ListClusters elasticmapreduce
elasticmapreduce:ListSecurityConfigurations elasticmapreduce
es:DescribeDomain es
es:DescribeDomainConfig es
es:DescribeDomains es
es:ListDomainNames es
events:DeleteRule events
events:DescribeRule events
events:DescribeRule events
events:DisableRule events
events:EnableRule events
events:ListConnections events
events:ListEventBuses events
events:ListEventSources events
events:ListRules events
events:ListTargetsByRule events
events:PutRule events
events:PutTargets events
events:RemoveTargets events
firehose:ListDeliveryStreams firehose
fsx:DescribeFileSystems fsx
guardduty:ListDetectors guardduty
iam:GenerateCredentialReport iam
iam:GetAccessKeyLastUsed iam
iam:GetAccountAuthorizationDetails iam
iam:GetAccountPasswordPolicy iam
iam:GetAccountSummary iam
iam:GetCredentialReport iam
iam:GetGroupPolicy iam
iam:GetPolicy iam
iam:GetPolicyVersion iam
iam:GetRolePolicy iam
iam:GetUser iam
iam:GetUserPolicy iam
iam:ListAccessKeys iam
iam:ListAttachedGroupPolicies iam
iam:ListAttachedRolePolicies iam
iam:ListAttachedUserPolicies iam
iam:ListEntitiesForPolicy iam
iam:ListGroupPolicies iam
iam:ListGroups iam
iam:ListGroupsForUser iam
iam:ListMfaDeviceTags iam
iam:ListMfaDevices iam
iam:ListOpenIdConnectProviders iam
iam:ListPolicies iam
iam:ListPolicyVersions iam
iam:ListRolePolicies iam
iam:ListRoles iam
iam:ListSamlProviders iam
iam:ListUserPolicies iam
iam:ListUsers iam
iam:ListVirtualMFADevices iam
kafka:ListClusters kafka
kafka:ListKafkaVersions kafka
kinesis:ListStreams kinesis
kms:DescribeKey kms
kms:GetKeyPolicy kms
kms:GetKeyRotationStatus kms
kms:ListGrants kms
kms:ListKeyPolicies kms
kms:ListKeys kms
lambda:ListFunctions lambda
license-manager:ListAssociationsForLicenseConfiguration license-manager
license-manager:ListLicenseConfigurations license-manager
license-manager:ListUsageForLicenseConfiguration license-manager
logs:DescribeDestinations logs
logs:DescribeExportTasks logs
logs:DescribeLogGroups logs
logs:DescribeMetricFilters logs
logs:DescribeResourcePolicies logs
logs:FilterLogEvents logs
logs:GetDataProtectionPolicy logs
organizations:DescribeOrganization organizations
organizations:DescribePolicy organizations
rds:DescribeCertificates rds
rds:DescribeDBClusterEndpoints rds
rds:DescribeDBClusterParameterGroups rds
rds:DescribeDBClusters rds
rds:DescribeDBInstanceAutomatedBackups rds
rds:DescribeDBInstances rds
rds:DescribeDBSecurityGroups rds
redshift:DescribeClusterSnapshots redshift
redshift:DescribeClusters redshift
redshift:DescribeLoggingStatus redshift
route53:GetQueryLoggingConfig route53
s3:GetBucketAcl s3
s3:GetBucketLogging s3
s3:GetBucketOwnershipControls s3
s3:GetBucketPolicy s3
s3:GetBucketPublicAccessBlock s3
s3:GetBucketTagging s3
s3:GetBucketVersioning s3
s3:GetEncryptionConfiguration s3
s3:GetLifecycleConfiguration s3
s3:ListAllMyBuckets s3
sagemaker:DescribeAlgorithm sagemaker
sagemaker:DescribeDomain sagemaker
sagemaker:DescribeEndpoint sagemaker
sagemaker:DescribeEndpointConfig sagemaker
sagemaker:DescribeFlowDefinition sagemaker
sagemaker:DescribeHumanTaskUi sagemaker
sagemaker:DescribeLabelingJob sagemaker
sagemaker:DescribeModel sagemaker
sagemaker:DescribeModelBiasJobDefinition sagemaker
sagemaker:DescribeModelCard sagemaker
sagemaker:DescribeModelQualityJobDefinition sagemaker
sagemaker:DescribeTrainingJob sagemaker
sagemaker:DescribeUserProfile sagemaker
sagemaker:ListAlgorithms sagemaker
sagemaker:ListDomains sagemaker
sagemaker:ListEndpointConfigs sagemaker
sagemaker:ListEndpoints sagemaker
sagemaker:ListFlowDefinitions sagemaker
sagemaker:ListHumanTaskUis sagemaker
sagemaker:ListLabelingJobs sagemaker
sagemaker:ListModelBiasJobDefinitions sagemaker
sagemaker:ListModelCards sagemaker
sagemaker:ListModelQualityJobDefinitions sagemaker
sagemaker:ListModels sagemaker
sagemaker:ListMonitoringAlerts sagemaker
sagemaker:ListMonitoringSchedules sagemaker
sagemaker:ListTrainingJobs sagemaker
sagemaker:ListUserProfiles sagemaker
secretsmanager:DescribeSecret secretsmanager
secretsmanager:ListSecrets secretsmanager
securityhub:DescribeStandards securityhub
sns:ListTagsForResource sns
sns:ListTopics sns
sqs:ListQueues sqs
waf:GetRule waf
waf:GetRuleGroup waf
waf:ListActivatedRulesInRuleGroup waf
waf:ListRuleGroups waf
waf:ListRules waf
waf:ListWebAcls waf
waf-regional:GetLoggingConfiguration waf-regional
waf-regional:GetRule waf-regional
waf-regional:GetWebAcl waf-regional
waf-regional:ListRuleGroups waf-regional
waf-regional:ListRules waf-regional
waf-regional:ListSubscribedRuleGroups waf-regional
waf-regional:ListWebACLs waf-regional
wafv2:ListWebAcls wafv2