View a markdown version of this page

Actions, resources, and condition keys for AWS Control Tower - Service Authorization Reference

Actions, resources, and condition keys for AWS Control Tower

AWS Control Tower (service prefix: controltower) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS Control Tower

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

CreateLandingZone

controltower:CreateLandingZone

Write

controltower:PerformPreLaunchChecks

Read

controltower:SetupLandingZone

Write

controltower:TagResource

Tagging, Write

DeleteLandingZone

controltower:DeleteLandingZone

Write

DisableBaseline

controltower:DeregisterOrganizationalUnit

Write

controltower:DisableBaseline

Write

DisableControl

controltower:DisableControl

Write

controltower:DisableGuardrail

Write

EnableBaseline

controltower:EnableBaseline

Write

controltower:ManageOrganizationalUnit

Write

controltower:TagResource

Tagging, Write

EnableControl

controltower:EnableControl

Write

controltower:EnableGuardrail

Write

controltower:TagResource

Tagging, Write

GetBaseline

controltower:GetBaseline

Read

GetBaselineOperation

controltower:DescribeRegisterOrganizationalUnitOperation

Read

controltower:GetBaselineOperation

Read

GetControlOperation

controltower:GetControlOperation

Read

GetEnabledBaseline

controltower:DescribeManagedAccount

Read

controltower:DescribeManagedOrganizationalUnit

Read

controltower:GetEnabledBaseline

Read

GetEnabledControl

controltower:DescribeGuardrailForTarget

Read

controltower:GetEnabledControl

Read

GetLandingZone

controltower:DescribeLandingZoneConfiguration

Read

controltower:GetAvailableUpdates

Read

controltower:GetLandingZone

Read

controltower:GetLandingZoneDriftStatus

Read

controltower:GetLandingZoneStatus

Read

GetLandingZoneOperation

controltower:GetLandingZoneOperation

Read

controltower:GetLandingZoneStatus

Read

ListBaselines

controltower:ListBaselines

List

ListControlOperations

controltower:ListControlOperations

List

ListEnabledBaselines

controltower:ListEnabledBaselines

List

controltower:ListManagedAccounts

List

controltower:ListManagedOrganizationalUnits

List

ListEnabledControls

controltower:ListEnabledControls

List

controltower:ListGuardrailsForTarget

List

ListLandingZoneOperations

controltower:GetLandingZoneStatus

Read

controltower:ListLandingZoneOperations

List

ListLandingZones

controltower:GetHomeRegion

Read

controltower:ListLandingZones

List

ListTagsForResource

controltower:ListTagsForResource

Read

ResetEnabledBaseline

controltower:ManageOrganizationalUnit

Write

controltower:ResetEnabledBaseline

Write

ResetEnabledControl

controltower:ResetEnabledControl

Write

ResetLandingZone

controltower:ResetLandingZone

Write

controltower:SetupLandingZone

Write

TagResource

controltower:TagResource

Tagging, Write

UntagResource

controltower:UntagResource

Tagging, Write

UpdateEnabledBaseline

controltower:ManageOrganizationalUnit

Write

controltower:UpdateEnabledBaseline

Write

UpdateEnabledControl

controltower:UpdateEnabledControl

Write

UpdateLandingZone

controltower:SetupLandingZone

Write

controltower:UpdateLandingZone

Write

Actions defined by AWS Control Tower

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

CreateLandingZone

Grants permission to create a landing zone

aws:RequestTag/${TagKey}

aws:TagKeys

Write

DeleteLandingZone

Grants permission to delete AWS Control Tower landing zone

LandingZone*

aws:ResourceTag/${TagKey}

Write

DisableBaseline

Grants permission to disable a Baseline on a target

EnabledBaseline*

aws:ResourceTag/${TagKey}

Write

DisableControl

Grants permission to remove a control from an organizational unit

EnabledControl*

aws:ResourceTag/${TagKey}

Write

EnableBaseline

Grants permission to enable a Baseline on a target

aws:RequestTag/${TagKey}

aws:TagKeys

Write

EnableControl

Grants permission to activate a control for an organizational unit

EnabledControl

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

GetBaseline

Grants permission to get Baseline details

Baseline*

Read

GetBaselineOperation

Grants permission to get the current status of a particular Baseline operation