View a markdown version of this page

Actions, resources, and condition keys for AWS Systems Manager - Service Authorization Reference

Actions, resources, and condition keys for AWS Systems Manager

AWS Systems Manager (service prefix: ssm) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS Systems Manager

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

AddTagsToResource

ssm:AddTagsToResource

Tagging, Write

AssociateOpsItemRelatedItem

ssm:AssociateOpsItemRelatedItem

Write

CancelCommand

ssm:CancelCommand

Write

CancelMaintenanceWindowExecution

ssm:CancelMaintenanceWindowExecution

Write

CreateActivation

ssm:AddTagsToResource

Tagging, Write

ssm:CreateActivation

Write

iam:PassRole

iam:PassedToService

ssm.amazonaws.com

Write

CreateAssociation

ssm:AddTagsToResource

Tagging, Write

ssm:CreateAssociation

Write

iam:PassRole

iam:PassedToService

ssm.amazonaws.com

Write

CreateAssociationBatch

ssm:CreateAssociation

Write

ssm:CreateAssociationBatch

Write

iam:PassRole

iam:PassedToService

ssm.amazonaws.com

Write

CreateCloudConnector

ssm:AddTagsToResource

Tagging, Write

ssm:CreateCloudConnector

Write

iam:PassRole

iam:PassedToService

ssm.amazonaws.com

Write

CreateDocument

ssm:AddTagsToResource

Tagging, Write

ssm:CreateDocument

Write

ssm:GetDocument

Read

iam:PassRole

iam:PassedToService

justintimeaccess.ssm.amazonaws.com, ssm.amazonaws.com

Write

CreateMaintenanceWindow

ssm:AddTagsToResource

Tagging, Write

ssm:CreateMaintenanceWindow

Write

CreateOpsItem

ssm:AddTagsToResource

Tagging, Write

ssm:CreateOpsItem

Write

CreateOpsMetadata