Skip to content

Policy: SystemAdministrator

ARN: arn:aws:iam::aws:policy/job-function/SystemAdministrator

Allowed Actions

Actions Services
acm:Describe* acm
acm:Get* acm
acm:List* acm
acm:Request* acm
acm:Resend* acm
autoscaling:* autoscaling
cloudtrail:DescribeTrails cloudtrail
cloudtrail:GetTrailStatus cloudtrail
cloudtrail:ListPublicKeys cloudtrail
cloudtrail:ListTags cloudtrail
cloudtrail:LookupEvents cloudtrail
cloudtrail:StartLogging cloudtrail
cloudtrail:StopLogging cloudtrail
cloudwatch:* cloudwatch
codecommit:BatchGetRepositories codecommit
codecommit:CreateBranch codecommit
codecommit:CreateRepository codecommit
codecommit:Get* codecommit
codecommit:GitPull codecommit
codecommit:GitPush codecommit
codecommit:List* codecommit
codecommit:Put* codecommit
codecommit:Test* codecommit
codecommit:Update* codecommit
codedeploy:* codedeploy
codepipeline:* codepipeline
config:* config
ds:* ds
ec2:AcceptVpcPeeringConnection ec2
ec2:Allocate* ec2
ec2:Allocate* ec2
ec2:AssignPrivateIpAddresses* ec2
ec2:Associate* ec2
ec2:AttachClassicLinkVpc ec2
ec2:AttachInternetGateway ec2
ec2:AttachNetworkInterface ec2
ec2:AttachVolume ec2
ec2:AttachVpnGateway ec2
ec2:AuthorizeSecurityGroupEgress ec2
ec2:AuthorizeSecurityGroupIngress ec2
ec2:Bundle* ec2
ec2:Cancel* ec2
ec2:Copy* ec2
ec2:CreateCustomerGateway ec2
ec2:CreateDhcpOptions ec2
ec2:CreateFlowLogs ec2
ec2:CreateImage ec2
ec2:CreateInstanceExportTask ec2
ec2:CreateInternetGateway ec2
ec2:CreateKeyPair ec2
ec2:CreateLaunchTemplate ec2
ec2:CreateLaunchTemplateVersion ec2
ec2:CreateNatGateway ec2
ec2:CreateNetworkInterface ec2
ec2:CreatePlacementGroup ec2
ec2:CreateReservedInstancesListing ec2
ec2:CreateRoute ec2
ec2:CreateRouteTable ec2
ec2:CreateSecurityGroup ec2
ec2:CreateSnapshot ec2
ec2:CreateSpotDatafeedSubscription ec2
ec2:CreateSubnet ec2
ec2:CreateTags ec2
ec2:CreateVolume ec2
ec2:CreateVpc ec2
ec2:CreateVpcEndpoint ec2
ec2:CreateVpcPeeringConnection ec2
ec2:CreateVpnConnection ec2
ec2:CreateVpnConnectionRoute ec2
ec2:CreateVpnGateway ec2
ec2:DeleteCustomerGateway ec2
ec2:DeleteDhcpOptions ec2
ec2:DeleteFlowLogs ec2
ec2:DeleteInternetGateway ec2
ec2:DeleteKeyPair ec2
ec2:DeleteLaunchTemplate ec2
ec2:DeleteLaunchTemplateVersions ec2
ec2:DeleteNatGateway ec2
ec2:DeleteNetworkAcl* ec2
ec2:DeleteNetworkInterface ec2
ec2:DeletePlacementGroup ec2
ec2:DeleteRoute ec2
ec2:DeleteRouteTable ec2
ec2:DeleteSecurityGroup ec2
ec2:DeleteSnapshot ec2
ec2:DeleteSpotDatafeedSubscription ec2
ec2:DeleteSubnet ec2
ec2:DeleteTags ec2
ec2:DeleteVolume ec2
ec2:DeleteVpc ec2
ec2:DeleteVpcEndpoints ec2
ec2:DeleteVpcPeeringConnection ec2
ec2:DeleteVpnConnection ec2
ec2:DeleteVpnConnectionRoute ec2
ec2:DeleteVpnGateway ec2
ec2:DeregisterImage ec2
ec2:Describe* ec2
ec2:DetachClassicLinkVpc ec2
ec2:DetachInternetGateway ec2
ec2:DetachNetworkInterface ec2
ec2:DetachVolume ec2
ec2:DetachVpnGateway ec2
ec2:DisableVgwRoutePropagation ec2
ec2:DisableVpcClassicLink ec2
ec2:DisableVpcClassicLinkDnsSupport ec2
ec2:DisassociateAddress ec2
ec2:DisassociateRouteTable ec2
ec2:EnableVgwRoutePropagation ec2
ec2:EnableVolumeIO ec2
ec2:EnableVpcClassicLink ec2
ec2:EnableVpcClassicLinkDnsSupport ec2
ec2:GetConsoleOutput ec2
ec2:GetConsoleScreenshot ec2
ec2:GetHostReservationPurchasePreview ec2
ec2:GetLaunchTemplateData ec2
ec2:GetPasswordData ec2
ec2:GetSecurityGroupsForVpc ec2
ec2:Import* ec2
ec2:Modify* ec2
ec2:MonitorInstances ec2
ec2:MoveAddressToVpc ec2
ec2:Purchase* ec2
ec2:RebootInstances ec2
ec2:RegisterImage ec2
ec2:RejectVpcPeeringConnection ec2
ec2:Release* ec2
ec2:Replace* ec2
ec2:ReportInstanceStatus ec2
ec2:Request* ec2
ec2:Reset* ec2
ec2:RestoreAddressToClassic ec2
ec2:RevokeSecurityGroupEgress ec2
ec2:RevokeSecurityGroupIngress ec2
ec2:RunInstances ec2
ec2:RunScheduledInstances ec2
ec2:StartInstances ec2
ec2:StopInstances ec2
ec2:TerminateInstances ec2
ec2:UnassignPrivateIpAddresses ec2
ec2:UnmonitorInstances ec2
ec2:UpdateSecurityGroupRuleDescriptionsEgress ec2
ec2:UpdateSecurityGroupRuleDescriptionsIngress ec2
elasticloadbalancing:* elasticloadbalancing
events:* events
iam:GetAccessKeyLastUsed iam
iam:GetAccount* iam
iam:GetContextKeys* iam
iam:GetCredentialReport iam
iam:GetGroup* iam
iam:GetInstanceProfile iam
iam:GetLoginProfile iam
iam:GetOpenIDConnectProvider iam
iam:GetPolicy* iam
iam:GetRole iam
iam:GetRole* iam
iam:GetSAMLProvider iam
iam:GetSSHPublicKey iam
iam:GetServerCertificate iam
iam:GetServiceLastAccessed* iam
iam:GetUser* iam
iam:ListAccessKeys iam
iam:ListAccountAliases iam
iam:ListAttached* iam
iam:ListEntitiesForPolicy iam
iam:ListGroupPolicies iam
iam:ListGroups iam
iam:ListGroupsForUser iam
iam:ListInstanceProfiles* iam
iam:ListMFADevices iam
iam:ListOpenIDConnectProviders iam
iam:ListPolicies iam
iam:ListPoliciesGrantingServiceAccess iam
iam:ListPolicyVersions iam
iam:ListRolePolicies iam
iam:ListRoles iam
iam:ListRoles iam
iam:ListSAMLProviders iam
iam:ListSSHPublicKeys iam
iam:ListServerCertificates iam
iam:ListSigningCertificates iam
iam:ListUserPolicies iam
iam:PassRole iam
iam:Simulate* iam
iam:UpdateServerCertificate iam
iam:UpdateSigningCertificate iam
iam:Upload* iam
kinesis:ListStreams kinesis
kinesis:PutRecord kinesis
kms:CreateAlias kms
kms:CreateKey kms
kms:DeleteAlias kms
kms:Describe* kms
kms:Encrypt kms
kms:GenerateRandom kms
kms:Get* kms
kms:List* kms
kms:ReEncrypt* kms
lambda:Create* lambda
lambda:Delete* lambda
lambda:Get* lambda
lambda:InvokeFunction lambda
lambda:List* lambda
lambda:PublishVersion lambda
lambda:Update* lambda
logs:* logs
rds:Describe* rds
rds:ListTagsForResource rds
route53:* route53
route53domains:* route53domains
s3:* s3
ses:* ses
sns:* sns
sqs:* sqs
trustedadvisor:* trustedadvisor