AWS Security ChangesHomeSearch

AWS AWSEC2: Clarified IAM tag manipulation risk warning

Service: AWSEC2 · 2026-08-16 · Documentation low

File: AWSEC2/latest/UserGuide/iam-policies-ec2-console.md · Type: iam

Summary

Changed 'in order to bypass' to 'to bypass' in tag-based access control warning.

Security assessment

Simplifies phrasing without altering the security warning about IAM tag manipulation risks.

Evidence

+Specifying a **Name** while launching an instance creates a tag and requires the `ec2:CreateTags` action. Be careful about granting users permission to use the `ec2:CreateTags` action, because doing so limits your ability to use the `aws:ResourceTag` condition key to restrict their use of other resources. If you grant users permission to use the `ec2:CreateTags` action, they can change a resource's tag to bypass those restrictions. For more information, see [Control access using attribute-based access](./iam-policies-for-amazon-ec2.html#control-access-with-tags).

Diff

diff --git a/AWSEC2/latest/UserGuide/iam-policies-ec2-console.md b/AWSEC2/latest/UserGuide/iam-policies-ec2-console.md
index bb9858724..2eb995adb 100644
--- a//AWSEC2/latest/UserGuide/iam-policies-ec2-console.md
+++ b//AWSEC2/latest/UserGuide/iam-policies-ec2-console.md
@@ -171 +171 @@ You can add API actions to your policy to provide more options for users, for ex
-Specifying a **Name** while launching an instance creates a tag and requires the `ec2:CreateTags` action. Be careful about granting users permission to use the `ec2:CreateTags` action, because doing so limits your ability to use the `aws:ResourceTag` condition key to restrict their use of other resources. If you grant users permission to use the `ec2:CreateTags` action, they can change a resource's tag in order to bypass those restrictions. For more information, see [Control access using attribute-based access](./iam-policies-for-amazon-ec2.html#control-access-with-tags).
+Specifying a **Name** while launching an instance creates a tag and requires the `ec2:CreateTags` action. Be careful about granting users permission to use the `ec2:CreateTags` action, because doing so limits your ability to use the `aws:ResourceTag` condition key to restrict their use of other resources. If you grant users permission to use the `ec2:CreateTags` action, they can change a resource's tag to bypass those restrictions. For more information, see [Control access using attribute-based access](./iam-policies-for-amazon-ec2.html#control-access-with-tags).