AWS Security ChangesHomeSearch

AWS guardduty: Document VPC Lattice permissions added to AmazonGuardDutyServiceRolePolicy

Service: guardduty · 2026-09-27 · Documentation medium

File: guardduty/latest/ug/security-iam-awsmanpol.md · Type: iam

Summary

Adds a changelog entry and policy snippet showing two new statements (GdLatticeCreateManagedSnvaAssociation and GdLatticeAssociateViaAwsService) granting vpc-lattice:CreateServiceNetworkVpcAssociation and vpc-lattice:AssociateViaAWSService to the GuardDuty service-linked role policy.

Security assessment

The change documents an expansion of the GuardDuty service-linked role IAM policy with VPC Lattice permissions, scoped by an aws:ResourceAccount condition for the create statement. It is IAM permission documentation with security impact (privilege scope of an AWS service role) but does not remediate a vulnerability.

Evidence

+[AmazonGuardDutyServiceRolePolicy](./slr-permissions.html) – Update to an existing policy |  Added the `vpc-lattice:CreateServiceNetworkVpcAssociation` and `vpc-lattice:AssociateViaAWSService` permissions, which allow GuardDuty to use Amazon VPC Lattice actions to enable connectivity for the Runtime Monitoring agent. The `GdLatticeCreateManagedSnvaAssociation` statement allows GuardDuty to create a service network VPC association for resources in the same account. The `GdLatticeAssociateViaAwsService` statement allows GuardDuty to complete the association through Amazon VPC Lattice.

Diff

diff --git a/guardduty/latest/ug/security-iam-awsmanpol.md b/guardduty/latest/ug/security-iam-awsmanpol.md
index 0b3ec82b2..b89b336d5 100644
--- a//guardduty/latest/ug/security-iam-awsmanpol.md
+++ b//guardduty/latest/ug/security-iam-awsmanpol.md
@@ -111,0 +112,22 @@ Change | Description | Date
+[AmazonGuardDutyServiceRolePolicy](./slr-permissions.html) – Update to an existing policy |  Added the `vpc-lattice:CreateServiceNetworkVpcAssociation` and `vpc-lattice:AssociateViaAWSService` permissions, which allow GuardDuty to use Amazon VPC Lattice actions to enable connectivity for the Runtime Monitoring agent. The `GdLatticeCreateManagedSnvaAssociation` statement allows GuardDuty to create a service network VPC association for resources in the same account. The `GdLatticeAssociateViaAwsService` statement allows GuardDuty to complete the association through Amazon VPC Lattice.
+    
+    
+    {
+                                    "Sid": "GdLatticeCreateManagedSnvaAssociation",
+                                    "Effect": "Allow",
+                                    "Action": "vpc-lattice:CreateServiceNetworkVpcAssociation",
+                                    "Resource": "arn:aws:vpc-lattice:*:*:servicenetworkvpcassociation/*",
+                                    "Condition": {
+                                        "StringEquals": {
+                                            "aws:ResourceAccount": "${aws:PrincipalAccount}"
+                                        }
+                                    }
+                                },
+                                {
+                                    "Sid": "GdLatticeAssociateViaAwsService",
+                                    "Effect": "Allow",
+                                    "Action": "vpc-lattice:AssociateViaAWSService",
+                                    "Resource": "*"
+                                }
+
+| September 9, 2026