AWS Lambda functions now support full IAM resource-based policies
Share
Services
AWS Lambda functions now support full Identity and Access Management (IAM) [resource-based policies](https://docs.aws.amazon.com/IAM/latest/UserGuide/access%5Fcontrolling.html#access%5Fcontrolling-resources), enabling platform admins and security teams to define granular access permissions using the full capabilities of AWS IAM. With full IAM resource-based policies, you can define permissions for multiple principals and actions in a single policy document and leverage the full range of [IAM condition keys](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference%5Fpolicies%5Fcondition-keys.html).
Previously, Lambda functions required customers to add permissions individually per principal. This provided limited flexibility for platform admins and security teams who want to manage permissions at scale. Now, Lambda functions support full IAM resource-based policies, including the full range of IAM condition keys. This provides a broader range of policy capabilities and streamlines policy management for teams operating multi-account architectures or managing multiple resources. For example, you can now use IAM condition keys to restrict access based on source IP or principal tag, and platform teams can now allow multiple services to invoke a function by using a single policy, rather than maintaining multiple statements to add permissions.
You can update resource-based policies in one step using the JSON editor in the AWS Lambda console, AWS CLI, AWS SDK, or infrastructure as code tools such as AWS CloudFormation and AWS SAM. To learn more, explore the [Lambda resource-based policy examples](https://docs.aws.amazon.com/lambda/latest/dg/access-control-resource-based.html) in the AWS Lambda Developer Guide.
Full IAM resource-based policies are available in all [AWS commerical Regions](https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/) at no additional charge.
What else is happening at Amazon Web Services?
Amazon ECS now automatically detects and repairs container instances with impaired agent connectivity
about 13 hours ago
Services
Share
Read update
Services
Share
Read update
Services
Share
Amazon Connect Customer now supports information extraction for agent voice and chat conversations
about 21 hours ago
Services
Share
OpenAI GPT-5.6 Terra and Luna now available on Amazon Bedrock in AWS GovCloud (US)
about 23 hours ago
Services
Share