AWS Security ChangesHomeSearch

AWS organizations: Note on AWS Organizations service-linked role managed policy

Service: organizations · 2026-09-27 · Documentation low

File: organizations/latest/userguide/orgs_reference_available-policies.md · Type: iam

Summary

Adds a note clarifying that the AWS managed policy attached to the AWSServiceRoleForOrganizations service-linked role is managed by AWS Organizations and cannot be attached to customer IAM users or roles.

Security assessment

The added note documents IAM/service-linked-role permission boundaries, clarifying that the Organizations SLR policy is AWS-managed and not attachable to customer principals. This is IAM guidance but does not address a specific vulnerability.

Evidence

For the AWS managed policy that is attached to the AWS Organizations service-linked role (`AWSServiceRoleForOrganizations`), which AWS Organizations uses to perform management actions in your accounts, see [AWS Organizations and service-linked roles](./orgs_integrate_services.html#orgs_integrate_services-using_slrs). Service-linked role permissions are managed by AWS Organizations and you can't attach that policy to your own IAM users or roles.

Diff

diff --git a/organizations/latest/userguide/orgs_reference_available-policies.md b/organizations/latest/userguide/orgs_reference_available-policies.md
index 68b19bca0..9e81cd962 100644
--- a//organizations/latest/userguide/orgs_reference_available-policies.md
+++ b//organizations/latest/userguide/orgs_reference_available-policies.md
@@ -20,0 +21,4 @@ You can use the following managed policies to grant permissions to users in your
+###### Note
+
+For the AWS managed policy that is attached to the AWS Organizations service-linked role (`AWSServiceRoleForOrganizations`), which AWS Organizations uses to perform management actions in your accounts, see [AWS Organizations and service-linked roles](./orgs_integrate_services.html#orgs_integrate_services-using_slrs). Service-linked role permissions are managed by AWS Organizations and you can't attach that policy to your own IAM users or roles.
+