2026-06-13
9 new actions, 1 new resource, 1 new condition | 2 updated actions
Additions
Actions
-
Authenticate
-
Description:
Grants permission to authenticate to the AWS Management Console
-
Access:
Read
-
Resources:
Name: console
Required: Yes
-
Conditions:
signin:PrincipalArn
-
CreateAccount
-
Description:
Grants permission to create an AWS account through the AWS Management Console sign-up flow
-
Access:
Write
-
Resources:
Name: console
Required: Yes
-
DeleteConsoleAuthorizationConfiguration
-
Description:
Grants permission to disable console authorization configuration for an AWS account or organization
-
Access:
Write
-
DeleteResourcePermissionStatement
-
Description:
Grants permission to remove a permission statement from the account's SignIn Resource Based Policy
-
Access:
Write
-
GetConsoleAuthorizationConfiguration
-
Description:
Grants permission to retrieve console authorization configuration for an AWS account or organization
-
Access:
Read
-
GetResourcePolicy
-
Description:
Grants permission to retrieve SignIn Resource Based Policy document that is attached with your account
-
Access:
Read
-
ListResourcePermissionStatements
-
Description:
Grants permission to list the SignIn Resource Based Policy statements in your account
-
Access:
List
-
PutConsoleAuthorizationConfiguration
-
Description:
Grants permission to enable console authorization configuration for an AWS account or organization
-
Access:
Write
-
PutResourcePermissionStatement
-
Description:
Grants permission to create a permission statement in the account's SignIn resource-based policy
-
Access:
Write
Resources
-
console
-
Arn:
arn:${Partition}:signin:::console/${ConsoleName}
Conditions
-
signin:PrincipalArn
-
Description:
Filters access by the principal ARN during pre-authentication console sign-in
-
Type:
ARN