AWS organizations: Note on AWS Organizations service-linked role managed policy
Summary
Adds a note clarifying that the AWS managed policy attached to the AWSServiceRoleForOrganizations service-linked role is managed by AWS Organizations and cannot be attached to customer IAM users or roles.
Security assessment
The added note documents IAM/service-linked-role permission boundaries, clarifying that the Organizations SLR policy is AWS-managed and not attachable to customer principals. This is IAM guidance but does not address a specific vulnerability.
Evidence
For the AWS managed policy that is attached to the AWS Organizations service-linked role (`AWSServiceRoleForOrganizations`), which AWS Organizations uses to perform management actions in your accounts, see [AWS Organizations and service-linked roles](./orgs_integrate_services.html#orgs_integrate_services-using_slrs). Service-linked role permissions are managed by AWS Organizations and you can't attach that policy to your own IAM users or roles.
Diff
diff --git a/organizations/latest/userguide/orgs_reference_available-policies.md b/organizations/latest/userguide/orgs_reference_available-policies.md index 68b19bca0..9e81cd962 100644 --- a//organizations/latest/userguide/orgs_reference_available-policies.md +++ b//organizations/latest/userguide/orgs_reference_available-policies.md @@ -20,0 +21,4 @@ You can use the following managed policies to grant permissions to users in your +###### Note + +For the AWS managed policy that is attached to the AWS Organizations service-linked role (`AWSServiceRoleForOrganizations`), which AWS Organizations uses to perform management actions in your accounts, see [AWS Organizations and service-linked roles](./orgs_integrate_services.html#orgs_integrate_services-using_slrs). Service-linked role permissions are managed by AWS Organizations and you can't attach that policy to your own IAM users or roles. +