Skip to content

Policy: FMSServiceRolePolicy

ARN: arn:aws:iam::aws:policy/aws-service-role/FMSServiceRolePolicy

Allowed Actions

Actions Services
apigateway:SetWebACL apigateway
cloudfront:GetDistribution cloudfront
cloudfront:ListDistributions cloudfront
cloudfront:ListDistributionsByWebACLId cloudfront
cloudfront:ListTagsForResource cloudfront
cloudfront:UpdateDistribution cloudfront
config:BatchGetResourceConfig config
config:DeleteConfigRule config
config:DeleteEvaluationResults config
config:DescribeComplianceByConfigRule config
config:DescribeConfigRuleEvaluationStatus config
config:DescribeConfigRules config
config:DescribeConfigurationRecorderStatus config
config:DescribeConfigurationRecorders config
config:DescribeDeliveryChannelStatus config
config:DescribeDeliveryChannels config
config:GetComplianceDetailsByConfigRule config
config:GetComplianceSummaryByConfigRule config
config:GetDiscoveredResourceCounts config
config:PutConfigRule config
config:PutConfigurationRecorder config
config:PutDeliveryChannel config
config:PutEvaluations config
config:SelectResourceConfig config
config:StartConfigRulesEvaluation config
config:StartConfigurationRecorder config
ec2:AssociateRouteTable ec2
ec2:AuthorizeSecurityGroupEgress ec2
ec2:AuthorizeSecurityGroupIngress ec2
ec2:CreateNetworkAcl ec2
ec2:CreateNetworkAclEntry ec2
ec2:CreateRouteTable ec2
ec2:CreateSecurityGroup ec2
ec2:CreateSubnet ec2
ec2:CreateTags ec2
ec2:CreateTags ec2
ec2:CreateTags ec2
ec2:CreateTags ec2
ec2:CreateTags ec2
ec2:CreateTags ec2
ec2:CreateTags ec2
ec2:CreateVpcEndpoint ec2
ec2:CreateVpcEndpoint ec2
ec2:DeleteNetworkAcl ec2
ec2:DeleteNetworkAclEntry ec2
ec2:DeleteRouteTable ec2
ec2:DeleteSecurityGroup ec2
ec2:DeleteSubnet ec2
ec2:DeleteTags ec2
ec2:DeleteTags ec2
ec2:DeleteVpcEndpoints ec2
ec2:DescribeAddresses ec2
ec2:DescribeAvailabilityZones ec2
ec2:DescribeInstances ec2
ec2:DescribeInternetGateways ec2
ec2:DescribeNetworkAcls ec2
ec2:DescribeNetworkInterfaceAttribute ec2
ec2:DescribeNetworkInterfaces ec2
ec2:DescribeRouteTables ec2
ec2:DescribeSecurityGroupReferences ec2
ec2:DescribeSecurityGroups ec2
ec2:DescribeStaleSecurityGroups ec2
ec2:DescribeSubnets ec2
ec2:DescribeTags ec2
ec2:DescribeVpcEndpoints ec2
ec2:DescribeVpcPeeringConnections ec2
ec2:DescribeVpcs ec2
ec2:DisassociateRouteTable ec2
ec2:ModifyNetworkInterfaceAttribute ec2
ec2:ReplaceNetworkAclAssociation ec2
ec2:ReplaceNetworkAclEntry ec2
ec2:ReplaceRouteTableAssociation ec2
ec2:RevokeSecurityGroupEgress ec2
ec2:RevokeSecurityGroupIngress ec2
ec2:UpdateSecurityGroupRuleDescriptionsEgress ec2
ec2:UpdateSecurityGroupRuleDescriptionsIngress ec2
elasticloadbalancing:ApplySecurityGroupsToLoadBalancer elasticloadbalancing
elasticloadbalancing:DescribeLoadBalancers elasticloadbalancing
elasticloadbalancing:DescribeTags elasticloadbalancing
elasticloadbalancing:SetSecurityGroups elasticloadbalancing
elasticloadbalancing:SetWebACL elasticloadbalancing
iam:CreateServiceLinkedRole iam
iam:DeleteServiceLinkedRole iam
iam:GetRole iam
iam:GetServiceLinkedRoleDeletionStatus iam
logs:CreateLogDelivery logs
logs:DeleteLogDelivery logs
logs:GetLogDelivery logs
logs:ListLogDeliveries logs
logs:UpdateLogDelivery logs
network-firewall:AssociateFirewallPolicy network-firewall
network-firewall:AssociateSubnets network-firewall
network-firewall:CreateFirewall network-firewall
network-firewall:CreateFirewallPolicy network-firewall
network-firewall:DeleteFirewall network-firewall
network-firewall:DeleteFirewallPolicy network-firewall
network-firewall:DeleteResourcePolicy network-firewall
network-firewall:DescribeFirewall network-firewall
network-firewall:DescribeFirewallPolicy network-firewall
network-firewall:DescribeLoggingConfiguration network-firewall
network-firewall:DescribeResourcePolicy network-firewall
network-firewall:DescribeRuleGroup network-firewall
network-firewall:DescribeTLSInspectionConfiguration network-firewall
network-firewall:DisassociateSubnets network-firewall
network-firewall:ListFirewallPolicies network-firewall
network-firewall:ListFirewalls network-firewall
network-firewall:ListRuleGroups network-firewall
network-firewall:ListTLSInspectionConfigurations network-firewall
network-firewall:PutResourcePolicy network-firewall
network-firewall:TagResource network-firewall
network-firewall:UpdateFirewallDeleteProtection network-firewall
network-firewall:UpdateFirewallPolicy network-firewall
network-firewall:UpdateFirewallPolicyChangeProtection network-firewall
network-firewall:UpdateLoggingConfiguration network-firewall
network-firewall:UpdateSubnetChangeProtection network-firewall
organizations:DescribeAccount organizations
organizations:DescribeOrganization organizations
organizations:DescribeOrganizationalUnit organizations
organizations:ListAWSServiceAccessForOrganization organizations
organizations:ListAccounts organizations
organizations:ListChildren organizations
organizations:ListOrganizationalUnitsForParent organizations
organizations:ListParents organizations
organizations:ListRoots organizations
ram:AssociateResourceShare ram
ram:CreateResourceShare ram
ram:DeleteResourceShare ram
ram:GetResourceShareAssociations ram
ram:GetResourceShares ram
ram:TagResource ram
ram:UpdateResourceShare ram
route53resolver:AssociateFirewallRuleGroup route53resolver
route53resolver:DisassociateFirewallRuleGroup route53resolver
route53resolver:GetFirewallRuleGroup route53resolver
route53resolver:GetFirewallRuleGroupAssociation route53resolver
route53resolver:GetFirewallRuleGroupPolicy route53resolver
route53resolver:ListFirewallRuleGroupAssociations route53resolver
route53resolver:ListFirewallRuleGroups route53resolver
route53resolver:ListTagsForResource route53resolver
route53resolver:PutFirewallRuleGroupPolicy route53resolver
route53resolver:TagResource route53resolver
route53resolver:UpdateFirewallRuleGroupAssociation route53resolver
shield:CreateProtection shield
shield:CreateSubscription shield
shield:DeleteProtection shield
shield:DescribeDRTAccess shield
shield:DescribeEmergencyContactSettings shield
shield:DescribeProtection shield
shield:DescribeSubscription shield
shield:DisableApplicationLayerAutomaticResponse shield
shield:EnableApplicationLayerAutomaticResponse shield
shield:GetSubscriptionState shield
shield:ListAttacks shield
shield:ListProtections shield
shield:UpdateApplicationLayerAutomaticResponse shield
shield:UpdateEmergencyContactSettings shield
waf:CreateWebACL waf
waf:DeletePermissionPolicy waf
waf:DeleteWebACL waf
waf:GetChangeToken waf
waf:GetPermissionPolicy waf
waf:GetRuleGroup waf
waf:GetWebACL waf
waf:ListSubscribedRuleGroups waf
waf:ListTagsForResource waf
waf:PutPermissionPolicy waf
waf:UpdateWebACL waf
waf-regional:AssociateWebACL waf-regional
waf-regional:CreateWebACL waf-regional
waf-regional:DeletePermissionPolicy waf-regional
waf-regional:DeleteWebACL waf-regional
waf-regional:DisassociateWebACL waf-regional
waf-regional:GetChangeToken waf-regional
waf-regional:GetPermissionPolicy waf-regional
waf-regional:GetRuleGroup waf-regional
waf-regional:GetWebACL waf-regional
waf-regional:GetWebACLForResource waf-regional
waf-regional:ListResourcesForWebACL waf-regional
waf-regional:ListSubscribedRuleGroups waf-regional
waf-regional:ListTagsForResource waf-regional
waf-regional:PutPermissionPolicy waf-regional
waf-regional:UpdateWebACL waf-regional
wafv2:AssociateWebACL wafv2
wafv2:CreateWebACL wafv2
wafv2:DeleteFirewallManagerRuleGroups wafv2
wafv2:DeleteLoggingConfiguration wafv2
wafv2:DeletePermissionPolicy wafv2
wafv2:DeleteWebACL wafv2
wafv2:DisassociateFirewallManager wafv2
wafv2:DisassociateWebACL wafv2
wafv2:GetLoggingConfiguration wafv2
wafv2:GetPermissionPolicy wafv2
wafv2:GetWebACL wafv2
wafv2:GetWebACLForResource wafv2
wafv2:ListLoggingConfigurations wafv2
wafv2:ListResourcesForWebACL wafv2
wafv2:ListTagsForResource wafv2
wafv2:PutFirewallManagerRuleGroups wafv2
wafv2:PutLoggingConfiguration wafv2
wafv2:PutPermissionPolicy wafv2
wafv2:TagResource wafv2
wafv2:UntagResource wafv2
wafv2:UpdateWebACL wafv2