View a markdown version of this page

Actions, resources, and condition keys for AWS Firewall Manager - Service Authorization Reference

Actions, resources, and condition keys for AWS Firewall Manager

AWS Firewall Manager (service prefix: fms) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS Firewall Manager

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

AssociateAdminAccount

fms:AssociateAdminAccount

Write

AssociateThirdPartyFirewall

fms:AssociateThirdPartyFirewall

Write

BatchAssociateResource

fms:BatchAssociateResource

Write

BatchDisassociateResource

fms:BatchDisassociateResource

Write

DeleteAppsList

fms:DeleteAppsList

Write

DeleteNotificationChannel

fms:DeleteNotificationChannel

Write

DeletePolicy

fms:DeletePolicy

Write

DeleteProtocolsList

fms:DeleteProtocolsList

Write

DeleteResourceSet

fms:DeleteResourceSet

Write

DisassociateAdminAccount

fms:DisassociateAdminAccount

Write