AWS guardduty: Document VPC Lattice permissions added to AmazonGuardDutyServiceRolePolicy
Summary
Adds a changelog entry and policy snippet showing two new statements (GdLatticeCreateManagedSnvaAssociation and GdLatticeAssociateViaAwsService) granting vpc-lattice:CreateServiceNetworkVpcAssociation and vpc-lattice:AssociateViaAWSService to the GuardDuty service-linked role policy.
Security assessment
The change documents an expansion of the GuardDuty service-linked role IAM policy with VPC Lattice permissions, scoped by an aws:ResourceAccount condition for the create statement. It is IAM permission documentation with security impact (privilege scope of an AWS service role) but does not remediate a vulnerability.
Evidence
+[AmazonGuardDutyServiceRolePolicy](./slr-permissions.html) – Update to an existing policy | Added the `vpc-lattice:CreateServiceNetworkVpcAssociation` and `vpc-lattice:AssociateViaAWSService` permissions, which allow GuardDuty to use Amazon VPC Lattice actions to enable connectivity for the Runtime Monitoring agent. The `GdLatticeCreateManagedSnvaAssociation` statement allows GuardDuty to create a service network VPC association for resources in the same account. The `GdLatticeAssociateViaAwsService` statement allows GuardDuty to complete the association through Amazon VPC Lattice.
Diff
diff --git a/guardduty/latest/ug/security-iam-awsmanpol.md b/guardduty/latest/ug/security-iam-awsmanpol.md index 0b3ec82b2..b89b336d5 100644 --- a//guardduty/latest/ug/security-iam-awsmanpol.md +++ b//guardduty/latest/ug/security-iam-awsmanpol.md @@ -111,0 +112,22 @@ Change | Description | Date +[AmazonGuardDutyServiceRolePolicy](./slr-permissions.html) – Update to an existing policy | Added the `vpc-lattice:CreateServiceNetworkVpcAssociation` and `vpc-lattice:AssociateViaAWSService` permissions, which allow GuardDuty to use Amazon VPC Lattice actions to enable connectivity for the Runtime Monitoring agent. The `GdLatticeCreateManagedSnvaAssociation` statement allows GuardDuty to create a service network VPC association for resources in the same account. The `GdLatticeAssociateViaAwsService` statement allows GuardDuty to complete the association through Amazon VPC Lattice. + + + { + "Sid": "GdLatticeCreateManagedSnvaAssociation", + "Effect": "Allow", + "Action": "vpc-lattice:CreateServiceNetworkVpcAssociation", + "Resource": "arn:aws:vpc-lattice:*:*:servicenetworkvpcassociation/*", + "Condition": { + "StringEquals": { + "aws:ResourceAccount": "${aws:PrincipalAccount}" + } + } + }, + { + "Sid": "GdLatticeAssociateViaAwsService", + "Effect": "Allow", + "Action": "vpc-lattice:AssociateViaAWSService", + "Resource": "*" + } + +| September 9, 2026