AWS Security ChangesHomeSearch

AWS organizations: Clarifies Action wildcard rules for customer managed RCPs

Service: organizations · 2026-09-27 · Documentation low

File: organizations/latest/userguide/orgs_manage_policies_rcps_syntax.md · Type: authz

Summary

Rewrites guidance on wildcard usage in the Action element, stating that a bare "*" is not permitted and that a service prefix must be specified, with examples like "s3:*" and "s3:Get*".

Security assessment

Documents a constraint that prevents overly broad RCP Action definitions, which is a guardrail against accidentally permissive or overly broad policy scoping. It is policy-syntax guidance rather than a fix for a specific vulnerability.

Evidence

In a customer managed RCP, you can't use `"*"` as the entire `Action` value. This wildcard by itself matches all actions in all services, which is not permitted. You must specify the abbreviation for a service (such as `"s3"`, `"sqs"`, or `"sts"`).

Diff

diff --git a/organizations/latest/userguide/orgs_manage_policies_rcps_syntax.md b/organizations/latest/userguide/orgs_manage_policies_rcps_syntax.md
index bfb18b090..0a2018308 100644
--- a//organizations/latest/userguide/orgs_manage_policies_rcps_syntax.md
+++ b//organizations/latest/userguide/orgs_manage_policies_rcps_syntax.md
@@ -136 +136 @@ You also can use wildcard characters such as asterisk (*) or question mark (?) i
-**Wildcards (*) and question marks (?) can be used anywhere in the action name**
+**You must specify a service in the Action element of a customer managed RCP**
@@ -138 +138 @@ You also can use wildcard characters such as asterisk (*) or question mark (?) i
-You cannot use "*" in the Action element of a customer managed RCP and have to specify the abbreviation for the service (such as "s3", "sqs", or "sts") you want to restrict access to.
+In a customer managed RCP, you can't use `"*"` as the entire `Action` value. This wildcard by itself matches all actions in all services, which is not permitted. You must specify the abbreviation for a service (such as `"s3"`, `"sqs"`, or `"sts"`). After the service, you can use the asterisk (*) wildcard to match actions within that service—for example, `"s3:*"` matches all Amazon S3 actions, and `"s3:Get*"` matches all Amazon S3 actions that begin with "Get." The question mark (?) wildcard matches a single character.