AWS organizations: Updates backup policy role name entry guidance in console
Summary
Changes instructions for entering a role name in the console for backup policies, removing the requirement to include a role/service-role prefix and stating only the role name should be entered.
Security assessment
This is a UI/console input clarification for backup policy role names. It touches IAM role references but does not document a security feature or address a vulnerability.
Evidence
In the console, you don't specify the entire Amazon Resource Name (ARN), and you don't include a prefix such as `role` or `service-role`. Enter only the role name. For example, enter `MyRoleName`. This is converted to a full ARN for you when stored in the underlying JSON.
Diff
diff --git a/organizations/latest/userguide/orgs_policies_create.md b/organizations/latest/userguide/orgs_policies_create.md index 7cc160957..1129cf175 100644 --- a//organizations/latest/userguide/orgs_policies_create.md +++ b//organizations/latest/userguide/orgs_policies_create.md @@ -472 +472 @@ For more information about backup rules, see [Backup Rules](https://docs.aws.ama -In the console, you don't specify the entire Amazon Resource Name (ARN). You must include both the role name and its prefix that specifies the type of role. The prefixes are typically `role` or `service-role` , and they are separated from the role name by a forward slash ('/'). For example, you might enter `role/MyRoleName` or `service-role/MyManagedRoleName`. This is converted to a full ARN for you when stored in the underlying JSON. +In the console, you don't specify the entire Amazon Resource Name (ARN), and you don't include a prefix such as `role` or `service-role`. Enter only the role name. For example, enter `MyRoleName`. This is converted to a full ARN for you when stored in the underlying JSON.