AWS organizations: Clarifies Action wildcard rules for customer managed RCPs
Summary
Rewrites guidance on wildcard usage in the Action element, stating that a bare "*" is not permitted and that a service prefix must be specified, with examples like "s3:*" and "s3:Get*".
Security assessment
Documents a constraint that prevents overly broad RCP Action definitions, which is a guardrail against accidentally permissive or overly broad policy scoping. It is policy-syntax guidance rather than a fix for a specific vulnerability.
Evidence
In a customer managed RCP, you can't use `"*"` as the entire `Action` value. This wildcard by itself matches all actions in all services, which is not permitted. You must specify the abbreviation for a service (such as `"s3"`, `"sqs"`, or `"sts"`).
Diff
diff --git a/organizations/latest/userguide/orgs_manage_policies_rcps_syntax.md b/organizations/latest/userguide/orgs_manage_policies_rcps_syntax.md index bfb18b090..0a2018308 100644 --- a//organizations/latest/userguide/orgs_manage_policies_rcps_syntax.md +++ b//organizations/latest/userguide/orgs_manage_policies_rcps_syntax.md @@ -136 +136 @@ You also can use wildcard characters such as asterisk (*) or question mark (?) i -**Wildcards (*) and question marks (?) can be used anywhere in the action name** +**You must specify a service in the Action element of a customer managed RCP** @@ -138 +138 @@ You also can use wildcard characters such as asterisk (*) or question mark (?) i -You cannot use "*" in the Action element of a customer managed RCP and have to specify the abbreviation for the service (such as "s3", "sqs", or "sts") you want to restrict access to. +In a customer managed RCP, you can't use `"*"` as the entire `Action` value. This wildcard by itself matches all actions in all services, which is not permitted. You must specify the abbreviation for a service (such as `"s3"`, `"sqs"`, or `"sts"`). After the service, you can use the asterisk (*) wildcard to match actions within that service—for example, `"s3:*"` matches all Amazon S3 actions, and `"s3:Get*"` matches all Amazon S3 actions that begin with "Get." The question mark (?) wildcard matches a single character.