View a markdown version of this page

Actions, resources, and condition keys for AWS IAM Identity Center directory - Service Authorization Reference

Actions, resources, and condition keys for AWS IAM Identity Center directory

AWS IAM Identity Center directory (service prefix: sso-directory) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

Actions defined by AWS IAM Identity Center directory

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

AddMemberToGroup

Grants permission to add a member to a group in the directory that AWS IAM Identity Center provides by default

Write

CompleteVirtualMfaDeviceRegistration

Grants permission to complete the creation process of a virtual MFA device

Write

CompleteWebAuthnDeviceRegistration

Grants permission to complete the registration process of a WebAuthn device

Write

CreateAlias

Grants permission to create an alias for the directory that AWS IAM Identity Center provides by default

Write

CreateBearerToken

Grants permission to create a bearer token for a given provisioning tenant

Write

CreateExternalIdPConfigurationForDirectory

Grants permission to create an External Identity Provider configuration for the directory

Write

CreateGroup

Grants permission to create a group in the directory that AWS IAM Identity Center provides by default

Write

CreateProvisioningTenant

Grants permission to create a provisioning tenant for a given directory

Write

CreateUser

Grants permission to create a user in the directory that AWS IAM Identity Center provides by default

Write

DeleteBearerToken

Grants permission to delete a bearer token

Write

DeleteExternalIdPCertificate

Grants permission to delete the given external IdP certificate

Write

DeleteExternalIdPConfigurationForDirectory

Grants permission to delete an External Identity Provider configuration associated with the directory

Write

DeleteGroup

Grants permission to delete a group from the directory that AWS IAM Identity Center provides by default

Write

DeleteMfaDeviceForUser

Grants permission to delete a MFA device by device name for a given user

Write

DeleteProvisioningTenant

Grants permission to delete the provisioning tenant

Write

DeleteUser

Grants permission to delete a user from the directory that AWS IAM Identity Center provides by default

Write

DescribeDirectory

Grants permission to retrieve information about the directory that AWS IAM Identity Center provides by default

Read

DescribeGroup

Grants permission to query the group data, not including user and group members

Read

DescribeGroups

Grants permission to retrieve information about groups from the directory that AWS IAM Identity Center provides by default

Read

DescribeProvisioningTenant

Grants permission to describes the provisioning tenant

Read

DescribeUser

Grants permission to retrieve information about a user from the directory that AWS IAM Identity Center provides by default

Read

DescribeUserByUniqueAttribute

Grants permission to describe user with a valid unique attribute represented for the user

Read

DescribeUsers

Grants permission to retrieve information about user from the directory that AWS IAM Identity Center provides by default

Read

DisableExternalIdPConfigurationForDirectory

Grants permission to disable authentication of end users with an External Identity Provider

Write

DisableUser

Grants permission to deactivate a user in the directory that AWS IAM Identity Center provides by default

Write

EnableExternalIdPConfigurationForDirectory

Grants permission to enable authentication of end users with an External Identity Provider

Write

EnableUser

Grants permission to activate user in the directory that AWS IAM Identity Center provides by default

Write

GetAWSSPConfigurationForDirectory

Grants permission to retrieve the AWS IAM Identity Center Service Provider configurations for the directory

Read