Amazon S3 adds additional policy details to access denied error messages
Share
Services
Amazon S3 now includes the specific AWS Identity and Access Management (IAM) and AWS Organizations policy Amazon Resource Name (ARN) in HTTP 403 Access Denied error messages for same-account and same-organization requests. This helps you quickly identify the exact policy responsible for a denied request and remediate the issue directly. Previously, S3 access denied error messages included the policy type and reason for denial, but when multiple policies of the same type existed, you still had to manually inspect each one to pinpoint the root cause. Now the error message includes the specific policy ARN for explicit deny cases, covering Service Control Policies (SCPs), Resource Control Policies (RCPs), identity-based policies, session policies, and permission boundaries. This capability is available in all AWS Regions, including the AWS GovCloud (US) Regions and the AWS China Regions. To learn more about how to troubleshoot access denied errors in Amazon S3, visit the [S3 User Guide](https://docs.aws.amazon.com/AmazonS3/latest/userguide/troubleshoot-403-errors.html) and the [IAM troubleshooting documentation](https://docs.aws.amazon.com/IAM/latest/UserGuide/troubleshoot%5Faccess-denied.html).
What else is happening at Amazon Web Services?
AWS Billing and Cost Management introduces Managed Dashboards
about 16 hours ago
Services
Share
Amazon Redshift adds rg.large and rg.12xlarge instance sizes in AWS GovCloud (US) Regions
about 22 hours ago
Services
Share
Read update
Services
Share