AWS Security ChangesHomeSearch

AWS organizations: Note on IAM Access Analyzer warning for organizations:PolicyType

Service: organizations · 2026-09-27 · Documentation medium

File: organizations/latest/userguide/security_iam_resource-based-policy-examples.md · Type: iam

Summary

Adds a note explaining that IAM Access Analyzer may warn that organizations:PolicyType is unsupported for certain actions, that these actions do support the key, and that StringLikeIfExists makes the condition safe.

Security assessment

The note clarifies behavior of a resource-based delegation policy condition key and the StringLikeIfExists operator, which affects authorization scoping. It is IAM policy guidance rather than a fix for a specific vulnerability.

Evidence

When you validate this policy, IAM Access Analyzer might return a warning that the `organizations:PolicyType` condition key isn't supported for the `DescribePolicy`, `DescribeEffectivePolicy`, `ListPolicies`, `ListPoliciesForTarget`, and `ListTargetsForPolicy` actions.

Diff

diff --git a/organizations/latest/userguide/security_iam_resource-based-policy-examples.md b/organizations/latest/userguide/security_iam_resource-based-policy-examples.md
index bf4114d87..964d0fc6c 100644
--- a//organizations/latest/userguide/security_iam_resource-based-policy-examples.md
+++ b//organizations/latest/userguide/security_iam_resource-based-policy-examples.md
@@ -90,0 +91,4 @@ This example delegation policy grants the permissions necessary to complete acti
+###### Note
+
+When you validate this policy, IAM Access Analyzer might return a warning that the `organizations:PolicyType` condition key isn't supported for the `DescribePolicy`, `DescribeEffectivePolicy`, `ListPolicies`, `ListPoliciesForTarget`, and `ListTargetsForPolicy` actions. These actions do support `organizations:PolicyType`, as documented in the [Actions, resources, and condition keys for AWS Organizations](https://docs.aws.amazon.com/service-authorization/latest/reference/list_awsorganizations.html) in the _Service Authorization Reference_. Because this example uses the `StringLikeIfExists` operator, the condition is enforced when the `organizations:PolicyType` key is present in the request and is ignored when the key is absent, so the delegation policy works as intended.
+