Skip to content

AWS Minimum Permissions

If you want to use a custom IAM policy, it must contain the minimum permissions SailPoint CIEM needs to read your AWS accounts. You'll use these permissions when configuring your AWS account automatically or manually.

Note

If you are using AWS for Identity Center provisioning, use the Identity Center Provisioning Policy Minimum Permissions, which contain both the minimum permissions and Identity Center-specific permissions.

Use the Commercial or GovCloud tab to view permissions for your AWS setup.

Minimum permissions
{
    "Version":"2012-10-17",
    "Statement":[
    {
        "Effect":"Allow",
        "Resource":"*",
        "Action":[
            "cloudtrail:DescribeTrails",
            "cloudtrail:GetEventSelectors",
            "cloudtrail:GetTrailStatus",
            "cloudtrail:ListTags",
            "cloudtrail:LookupEvents",
            "cloudwatch:Describe*",
            "cloudwatch:ListTagsForResource",
            "config:BatchGetAggregateResourceConfig",
            "config:BatchGetResourceConfig",
            "config:Deliver*",
            "config:Describe*",
            "config:Get*",
            "config:List*",
            "dynamodb:DescribeContinuousBackups",
            "dynamodb:DescribeGlobalTable",
            "dynamodb:DescribeTable",
            "dynamodb:DescribeTimeToLive",
            "dynamodb:ListBackups",
            "dynamodb:ListGlobalTables",
            "dynamodb:ListStreams",
            "dynamodb:ListTables",
            "dynamodb:ListTagsOfResource",
            "ec2:Describe*",
            "ec2:DescribeTransitGatewayAttachments",
            "ec2:DescribeTransitGatewayMulticastDomains",
            "ec2:DescribeTransitGatewayPeeringAttachments",
            "ec2:DescribeTransitGatewayRouteTables",
            "ec2:DescribeTransitGatewayVpcAttachments",
            "ec2:DescribeTransitGateways",
            "ec2:GetManagedPrefixListAssociations",
            "ec2:GetManagedPrefixListEntries",
            "ec2:GetTransitGatewayAttachmentPropagations",
            "ec2:GetTransitGatewayMulticastDomainAssociations",
            "ec2:GetTransitGatewayPrefixListReferences",
            "ec2:GetTransitGatewayRouteTableAssociations",
            "ec2:GetTransitGatewayRouteTablePropagations",
            "elasticloadbalancing:Describe*",
            "es:Describe*",
            "es:ListDomainNames",
            "es:ListElasticsearchInstanceTypeDetails",
            "es:ListElasticsearchVersions",
            "es:ListTags",
            "events:Describe*",
            "events:List*",
            "events:TestEventPattern",
            "iam:GenerateCredentialReport",
            "iam:GenerateServiceLastAccessedDetails",
            "iam:Get*",
            "iam:List*",
            "iam:SimulateCustomPolicy",
            "iam:SimulatePrincipalPolicy",
            "identitystore:ListUsers(1)",
            "identitystore:ListGroupMemberships",
            "identitystore:ListGroups",
            "kms:Describe*",
            "kms:Get*",
            "kms:List*",
            "lambda:GetAccountSettings",
            "lambda:GetFunctionConfiguration",
            "lambda:GetFunctionEventInvokeConfig",
            "lambda:GetLayerVersionPolicy",
            "lambda:GetPolicy",
            "lambda:List*",
            "logs:Describe*",
            "logs:ListTagsLogGroup",
            "organizations:Describe*",
            "organizations:List*",
            "rds:Describe*",
            "rds:DownloadDBLogFilePortion",
            "rds:ListTagsForResource",
            "s3:GetAccelerateConfiguration",
            "s3:GetAccessPoint",
            "s3:GetAccessPointPolicy",
            "s3:GetAccessPointPolicyStatus",
            "s3:GetAccountPublicAccessBlock",
            "s3:GetAnalyticsConfiguration",
            "s3:GetBucket*",
            "s3:GetEncryptionConfiguration",
            "s3:GetInventoryConfiguration",
            "s3:GetLifecycleConfiguration",
            "s3:GetMetricsConfiguration",
            "s3:GetObjectAcl",
            "s3:GetObjectVersionAcl",
            "s3:GetReplicationConfiguration",
            "s3:ListAccessPoints",
            "s3:ListAllMyBuckets",
            "sns:GetTopicAttributes",
            "sns:ListSubscriptions",
            "sns:ListSubscriptionsByTopic",
            "sns:ListTagsForResource",
            "sns:ListTopics",
            "sqs:GetQueueAttributes",
            "sqs:ListDeadLetterSourceQueues",
            "sqs:ListQueueTags",
            "sqs:ListQueues",
            "sso:DescribePermissionSet(2)",
            "sso:GetInlinePolicyForPermissionSet",
            "sso:GetPermissionsBoundaryForPermissionSet",
            "sso:ListAccountAssignments",
            "sso:ListAccountsForProvisionedPermissionSet",
            "sso:ListCustomerManagedPolicyReferencesInPermissionSet",
            "sso:ListInstances",
            "sso:ListManagedPoliciesInPermissionSet",
            "sso:ListPermissionSets", 
            "tag:GetResources",
            "tag:GetTagKeys"
        ]
    },
    {
        "Effect":"Allow",
        "Action":[
            "apigateway:GET"
        ],
        "Resource":[
            "arn:aws:apigateway:*::/apis",
            "arn:aws:apigateway:*::/apis/*/routes",
            "arn:aws:apigateway:*::/apis/*/stages",
            "arn:aws:apigateway:*::/apis/*/stages/*",
            "arn:aws:apigateway:*::/clientcertificates/*",
            "arn:aws:apigateway:*::/restapis",
            "arn:aws:apigateway:*::/restapis/*/authorizers",
            "arn:aws:apigateway:*::/restapis/*/authorizers/*",
            "arn:aws:apigateway:*::/restapis/*/documentation/versions",
            "arn:aws:apigateway:*::/restapis/*/resources",
            "arn:aws:apigateway:*::/restapis/*/resources/*",
            "arn:aws:apigateway:*::/restapis/*/resources/*/methods/*",
            "arn:aws:apigateway:*::/restapis/*/stages",
            "arn:aws:apigateway:*::/restapis/*/stages/*",
            "arn:aws:apigateway:*::/tags/*",
            "arn:aws:apigateway:*::/vpclinks"
        ]
    }
    ]
} 
  1. Identity store permissions are related to AWS Identity Center.
  2. SSO permissions are related to AWS Identity Center.
{
    "Version":"2012-10-17",
    "Statement":[
    {
        "Effect":"Allow",
        "Resource":"*",
        "Action":[
            "cloudtrail:DescribeTrails",
            "cloudtrail:GetEventSelectors",
            "cloudtrail:GetTrailStatus",
            "cloudtrail:ListTags",
            "cloudtrail:LookupEvents",
            "cloudwatch:Describe*",
            "cloudwatch:ListTagsForResource",
            "config:BatchGetAggregateResourceConfig",
            "config:BatchGetResourceConfig",
            "config:Deliver*",
            "config:Describe*",
            "config:Get*",
            "config:List*",
            "dynamodb:DescribeContinuousBackups",
            "dynamodb:DescribeGlobalTable",
            "dynamodb:DescribeTable",
            "dynamodb:DescribeTimeToLive",
            "dynamodb:ListBackups",
            "dynamodb:ListGlobalTables",
            "dynamodb:ListStreams",
            "dynamodb:ListTables",
            "dynamodb:ListTagsOfResource",
            "ec2:Describe*",
            "ec2:DescribeTransitGatewayAttachments",
            "ec2:DescribeTransitGatewayMulticastDomains",
            "ec2:DescribeTransitGatewayPeeringAttachments",
            "ec2:DescribeTransitGatewayRouteTables",
            "ec2:DescribeTransitGatewayVpcAttachments",
            "ec2:DescribeTransitGateways",
            "ec2:GetManagedPrefixListAssociations",
            "ec2:GetManagedPrefixListEntries",
            "ec2:GetTransitGatewayAttachmentPropagations",
            "ec2:GetTransitGatewayMulticastDomainAssociations",
            "ec2:GetTransitGatewayPrefixListReferences",
            "ec2:GetTransitGatewayRouteTableAssociations",
            "ec2:GetTransitGatewayRouteTablePropagations",
            "elasticloadbalancing:Describe*",
            "es:Describe*",
            "es:ListDomainNames",
            "es:ListElasticsearchInstanceTypeDetails",
            "es:ListElasticsearchVersions",
            "es:ListTags",
            "events:Describe*",
            "events:List*",
            "events:TestEventPattern",
            "iam:GenerateCredentialReport",
            "iam:GenerateServiceLastAccessedDetails",
            "iam:Get*",
            "iam:List*",
            "iam:SimulateCustomPolicy",
            "iam:SimulatePrincipalPolicy",
            "identitystore:ListUsers(1)",
            "identitystore:ListGroupMemberships",
            "identitystore:ListGroups",
            "kms:Describe*",
            "kms:Get*",
            "kms:List*",
            "lambda:GetAccountSettings",
            "lambda:GetFunctionConfiguration",
            "lambda:GetFunctionEventInvokeConfig",
            "lambda:GetLayerVersionPolicy",
            "lambda:GetPolicy",
            "lambda:List*",
            "logs:Describe*",
            "logs:ListTagsLogGroup",
            "organizations:Describe*",
            "organizations:List*",
            "rds:Describe*",
            "rds:DownloadDBLogFilePortion",
            "rds:ListTagsForResource",
            "s3:GetAccelerateConfiguration",
            "s3:GetAccessPoint",
            "s3:GetAccessPointPolicy",
            "s3:GetAccessPointPolicyStatus",
            "s3:GetAccountPublicAccessBlock",
            "s3:GetAnalyticsConfiguration",
            "s3:GetBucket*",
            "s3:GetEncryptionConfiguration",
            "s3:GetInventoryConfiguration",
            "s3:GetLifecycleConfiguration",
            "s3:GetMetricsConfiguration",
            "s3:GetObjectAcl",
            "s3:GetObjectVersionAcl",
            "s3:GetReplicationConfiguration",
            "s3:ListAccessPoints",
            "s3:ListAllMyBuckets",
            "sns:GetTopicAttributes",
            "sns:ListSubscriptions",
            "sns:ListSubscriptionsByTopic",
            "sns:ListTagsForResource",
            "sns:ListTopics",
            "sqs:GetQueueAttributes",
            "sqs:ListDeadLetterSourceQueues",
            "sqs:ListQueueTags",
            "sqs:ListQueues",
            "sso:DescribePermissionSet(2)",
            "sso:GetInlinePolicyForPermissionSet",
            "sso:GetPermissionsBoundaryForPermissionSet",
            "sso:ListAccountAssignments",
            "sso:ListAccountsForProvisionedPermissionSet",
            "sso:ListCustomerManagedPolicyReferencesInPermissionSet",
            "sso:ListInstances",
            "sso:ListManagedPoliciesInPermissionSet",
            "sso:ListPermissionSets", 
            "tag:GetResources",
            "tag:GetTagKeys"
        ]
    },
    {
        "Effect":"Allow",
        "Action":[
            "apigateway:GET"
        ],
        "Resource":[
            "arn:aws-us-gov:apigateway:*::/apis",
            "arn:aws-us-gov:apigateway:*::/apis/*/routes",
            "arn:aws-us-gov:apigateway:*::/apis/*/stages",
            "arn:aws-us-gov:apigateway:*::/apis/*/stages/*",
            "arn:aws-us-gov:apigateway:*::/clientcertificates/*",
            "arn:aws-us-gov:apigateway:*::/restapis",
            "arn:aws-us-gov:apigateway:*::/restapis/*/authorizers",
            "arn:aws-us-gov:apigateway:*::/restapis/*/authorizers/*",
            "arn:aws-us-gov:apigateway:*::/restapis/*/documentation/versions",
            "arn:aws-us-gov:apigateway:*::/restapis/*/resources",
            "arn:aws-us-gov:apigateway:*::/restapis/*/resources/*",
            "arn:aws-us-gov:apigateway:*::/restapis/*/resources/*/methods/*",
            "arn:aws-us-gov:apigateway:*::/restapis/*/stages",
            "arn:aws-us-gov:apigateway:*::/restapis/*/stages/*",
            "arn:aws-us-gov:apigateway:*::/tags/*",
            "arn:aws-us-gov:apigateway:*::/vpclinks"
        ]
    }
  ]
} 
  1. Identity store permissions are related to AWS Identity Center.
  2. SSO permissions are related to AWS Identity Center.

Identity Center Provisioning Policy Minimum Requirements

To use AWS Identity Center for provisioning, SailPoint CIEM requires additional permissions. The following policy includes the minimum permissions and the Identity Center provisioning requirements. Permissions specific to the Identity Center are highlighted.

Use the Commercial or GovCloud tab to view permissions for your AWS setup.

Identity Center provisioning permissions
{
  "Version":"2012-10-17",
  "Statement":[
  {
      "Effect":"Allow",
      "Resource":"*",
      "Action":[
          "cloudtrail:DescribeTrails",
          "cloudtrail:GetEventSelectors",
          "cloudtrail:GetTrailStatus",
          "cloudtrail:ListTags",
          "cloudtrail:LookupEvents",
          "cloudwatch:Describe*",
          "cloudwatch:ListTagsForResource",
          "config:BatchGetAggregateResourceConfig",
          "config:BatchGetResourceConfig",
          "config:Deliver*",
          "config:Describe*",
          "config:Get*",
          "config:List*",
          "dynamodb:DescribeContinuousBackups",
          "dynamodb:DescribeGlobalTable",
          "dynamodb:DescribeTable",
          "dynamodb:DescribeTimeToLive",
          "dynamodb:ListBackups",
          "dynamodb:ListGlobalTables",
          "dynamodb:ListStreams",
          "dynamodb:ListTables",
          "dynamodb:ListTagsOfResource",
          "ec2:Describe*",
          "ec2:DescribeTransitGatewayAttachments",
          "ec2:DescribeTransitGatewayMulticastDomains",
          "ec2:DescribeTransitGatewayPeeringAttachments",
          "ec2:DescribeTransitGatewayRouteTables",
          "ec2:DescribeTransitGatewayVpcAttachments",
          "ec2:DescribeTransitGateways",
          "ec2:GetManagedPrefixListAssociations",
          "ec2:GetManagedPrefixListEntries",
          "ec2:GetTransitGatewayAttachmentPropagations",
          "ec2:GetTransitGatewayMulticastDomainAssociations",
          "ec2:GetTransitGatewayPrefixListReferences",
          "ec2:GetTransitGatewayRouteTableAssociations",
          "ec2:GetTransitGatewayRouteTablePropagations",
          "elasticloadbalancing:Describe*",
          "es:Describe*",
          "es:ListDomainNames",
          "es:ListElasticsearchInstanceTypeDetails",
          "es:ListElasticsearchVersions",
          "es:ListTags",
          "events:Describe*",
          "events:List*",
          "events:TestEventPattern",
          "iam:GenerateCredentialReport",
          "iam:GenerateServiceLastAccessedDetails",
          "iam:Get*",
          "iam:List*",
          "iam:SimulateCustomPolicy",
          "iam:SimulatePrincipalPolicy",
          "identitystore:ListUsers",
          "identitystore:ListGroupMemberships",
          "identitystore:ListGroups",
          "kms:Describe*",
          "kms:Get*",
          "kms:List*",
          "lambda:GetAccountSettings",
          "lambda:GetFunctionConfiguration",
          "lambda:GetFunctionEventInvokeConfig",
          "lambda:GetLayerVersionPolicy",
          "lambda:GetPolicy",
          "lambda:List*",
          "logs:Describe*",
          "logs:ListTagsLogGroup",
          "organizations:Describe*",
          "organizations:List*",
          "rds:Describe*",
          "rds:DownloadDBLogFilePortion",
          "rds:ListTagsForResource",
          "s3:GetAccelerateConfiguration",
          "s3:GetAccessPoint",
          "s3:GetAccessPointPolicy",
          "s3:GetAccessPointPolicyStatus",
          "s3:GetAccountPublicAccessBlock",
          "s3:GetAnalyticsConfiguration",
          "s3:GetBucket*",
          "s3:GetEncryptionConfiguration",
          "s3:GetInventoryConfiguration",
          "s3:GetLifecycleConfiguration",
          "s3:GetMetricsConfiguration",
          "s3:GetObjectAcl",
          "s3:GetObjectVersionAcl",
          "s3:GetReplicationConfiguration",
          "s3:ListAccessPoints",
          "s3:ListAllMyBuckets",
          "sns:GetTopicAttributes",
          "sns:ListSubscriptions",
          "sns:ListSubscriptionsByTopic",
          "sns:ListTagsForResource",
          "sns:ListTopics",
          "sqs:GetQueueAttributes",
          "sqs:ListDeadLetterSourceQueues",
          "sqs:ListQueueTags",
          "sqs:ListQueues",
          "sso:DescribePermissionSet",
          "sso:GetInlinePolicyForPermissionSet",
          "sso:GetPermissionsBoundaryForPermissionSet",
          "sso:ListAccountAssignments",
          "sso:ListAccountsForProvisionedPermissionSet",
          "sso:ListCustomerManagedPolicyReferencesInPermissionSet",
          "sso:ListInstances",
          "sso:ListManagedPoliciesInPermissionSet",
          "sso:ListPermissionSets", 
          "tag:GetResources",
          "tag:GetTagKeys"
      ]
  },
  {
      "Effect":"Allow",
      "Action":[
          "apigateway:GET"
      ],
      "Resource":[
          "arn:aws:apigateway:*::/apis",
          "arn:aws:apigateway:*::/apis/*/routes",
          "arn:aws:apigateway:*::/apis/*/stages",
          "arn:aws:apigateway:*::/apis/*/stages/*",
          "arn:aws:apigateway:*::/clientcertificates/*",
          "arn:aws:apigateway:*::/restapis",
          "arn:aws:apigateway:*::/restapis/*/authorizers",
          "arn:aws:apigateway:*::/restapis/*/authorizers/*",
          "arn:aws:apigateway:*::/restapis/*/documentation/versions",
          "arn:aws:apigateway:*::/restapis/*/resources",
          "arn:aws:apigateway:*::/restapis/*/resources/*",
          "arn:aws:apigateway:*::/restapis/*/resources/*/methods/*",
          "arn:aws:apigateway:*::/restapis/*/stages",
          "arn:aws:apigateway:*::/restapis/*/stages/*",
          "arn:aws:apigateway:*::/tags/*",
          "arn:aws:apigateway:*::/vpclinks"
      ]
  },
  {
    "Effect": "Allow",
    "Resource": "*",
    "Action": [
        "identitystore:GetGroupMembershipId",
        "identitystore:GetUserId",
        "identitystore:CreateGroupMembership",
        "identitystore:CreateUser",
        "identitystore:DeleteGroupMembership",
        "identitystore:DeleteUser",
        "identitystore:UpdateUser",
        "sso:CreateAccountAssignment",
        "sso:DeleteAccountAssignment",
        "sso:ProvisionPermissionSet",
        "iam:CreateSAMLProvider",
        "iam:GetSAMLProvider",
        "iam:UpdateSAMLProvider",
        "iam:DeleteSAMLProvider",
        "iam:PutRolePolicy"
    ]
 }
  ]
} 
{
  "Version":"2012-10-17",
  "Statement":[
  {
      "Effect":"Allow",
      "Resource":"*",
      "Action":[
          "cloudtrail:DescribeTrails",
          "cloudtrail:GetEventSelectors",
          "cloudtrail:GetTrailStatus",
          "cloudtrail:ListTags",
          "cloudtrail:LookupEvents",
          "cloudwatch:Describe*",
          "cloudwatch:ListTagsForResource",
          "config:BatchGetAggregateResourceConfig",
          "config:BatchGetResourceConfig",
          "config:Deliver*",
          "config:Describe*",
          "config:Get*",
          "config:List*",
          "dynamodb:DescribeContinuousBackups",
          "dynamodb:DescribeGlobalTable",
          "dynamodb:DescribeTable",
          "dynamodb:DescribeTimeToLive",
          "dynamodb:ListBackups",
          "dynamodb:ListGlobalTables",
          "dynamodb:ListStreams",
          "dynamodb:ListTables",
          "dynamodb:ListTagsOfResource",
          "ec2:Describe*",
          "ec2:DescribeTransitGatewayAttachments",
          "ec2:DescribeTransitGatewayMulticastDomains",
          "ec2:DescribeTransitGatewayPeeringAttachments",
          "ec2:DescribeTransitGatewayRouteTables",
          "ec2:DescribeTransitGatewayVpcAttachments",
          "ec2:DescribeTransitGateways",
          "ec2:GetManagedPrefixListAssociations",
          "ec2:GetManagedPrefixListEntries",
          "ec2:GetTransitGatewayAttachmentPropagations",
          "ec2:GetTransitGatewayMulticastDomainAssociations",
          "ec2:GetTransitGatewayPrefixListReferences",
          "ec2:GetTransitGatewayRouteTableAssociations",
          "ec2:GetTransitGatewayRouteTablePropagations",
          "elasticloadbalancing:Describe*",
          "es:Describe*",
          "es:ListDomainNames",
          "es:ListElasticsearchInstanceTypeDetails",
          "es:ListElasticsearchVersions",
          "es:ListTags",
          "events:Describe*",
          "events:List*",
          "events:TestEventPattern",
          "iam:GenerateCredentialReport",
          "iam:GenerateServiceLastAccessedDetails",
          "iam:Get*",
          "iam:List*",
          "iam:SimulateCustomPolicy",
          "iam:SimulatePrincipalPolicy",
          "identitystore:ListUsers",
          "identitystore:ListGroupMemberships",
          "identitystore:ListGroups",
          "kms:Describe*",
          "kms:Get*",
          "kms:List*",
          "lambda:GetAccountSettings",
          "lambda:GetFunctionConfiguration",
          "lambda:GetFunctionEventInvokeConfig",
          "lambda:GetLayerVersionPolicy",
          "lambda:GetPolicy",
          "lambda:List*",
          "logs:Describe*",
          "logs:ListTagsLogGroup",
          "organizations:Describe*",
          "organizations:List*",
          "rds:Describe*",
          "rds:DownloadDBLogFilePortion",
          "rds:ListTagsForResource",
          "s3:GetAccelerateConfiguration",
          "s3:GetAccessPoint",
          "s3:GetAccessPointPolicy",
          "s3:GetAccessPointPolicyStatus",
          "s3:GetAccountPublicAccessBlock",
          "s3:GetAnalyticsConfiguration",
          "s3:GetBucket*",
          "s3:GetEncryptionConfiguration",
          "s3:GetInventoryConfiguration",
          "s3:GetLifecycleConfiguration",
          "s3:GetMetricsConfiguration",
          "s3:GetObjectAcl",
          "s3:GetObjectVersionAcl",
          "s3:GetReplicationConfiguration",
          "s3:ListAccessPoints",
          "s3:ListAllMyBuckets",
          "sns:GetTopicAttributes",
          "sns:ListSubscriptions",
          "sns:ListSubscriptionsByTopic",
          "sns:ListTagsForResource",
          "sns:ListTopics",
          "sqs:GetQueueAttributes",
          "sqs:ListDeadLetterSourceQueues",
          "sqs:ListQueueTags",
          "sqs:ListQueues",
          "sso:DescribePermissionSet",
          "sso:GetInlinePolicyForPermissionSet",
          "sso:GetPermissionsBoundaryForPermissionSet",
          "sso:ListAccountAssignments",
          "sso:ListAccountsForProvisionedPermissionSet",
          "sso:ListCustomerManagedPolicyReferencesInPermissionSet",
          "sso:ListInstances",
          "sso:ListManagedPoliciesInPermissionSet",
          "sso:ListPermissionSets", 
          "tag:GetResources",
          "tag:GetTagKeys"
      ]
  },
  {
      "Effect":"Allow",
      "Action":[
          "apigateway:GET"
      ],
      "Resource":[
          "arn:aws-us-gov:apigateway:*::/apis",
          "arn:aws-us-gov:apigateway:*::/apis/*/routes",
          "arn:aws-us-gov:apigateway:*::/apis/*/stages",
          "arn:aws-us-gov:apigateway:*::/apis/*/stages/*",
          "arn:aws-us-gov:apigateway:*::/clientcertificates/*",
          "arn:aws-us-gov:apigateway:*::/restapis",
          "arn:aws-us-gov:apigateway:*::/restapis/*/authorizers",
          "arn:aws-us-gov:apigateway:*::/restapis/*/authorizers/*",
          "arn:aws-us-gov:apigateway:*::/restapis/*/documentation/versions",
          "arn:aws-us-gov:apigateway:*::/restapis/*/resources",
          "arn:aws-us-gov:apigateway:*::/restapis/*/resources/*",
          "arn:aws-us-gov:apigateway:*::/restapis/*/resources/*/methods/*",
          "arn:aws-us-gov:apigateway:*::/restapis/*/stages",
          "arn:aws-us-gov:apigateway:*::/restapis/*/stages/*",
          "arn:aws-us-gov:apigateway:*::/tags/*",
          "arn:aws-us-gov:apigateway:*::/vpclinks"
      ]
  },
  {
    "Effect": "Allow",
    "Resource": "*",
    "Action": [
        "identitystore:GetGroupMembershipId",
        "identitystore:GetUserId",
        "identitystore:CreateGroupMembership",
        "identitystore:CreateUser",
        "identitystore:DeleteGroupMembership",
        "identitystore:DeleteUser",
        "identitystore:UpdateUser",
        "sso:CreateAccountAssignment",
        "sso:DeleteAccountAssignment",
        "sso:ProvisionPermissionSet",
        "iam:CreateSAMLProvider",
        "iam:GetSAMLProvider",
        "iam:UpdateSAMLProvider",
        "iam:DeleteSAMLProvider",
        "iam:PutRolePolicy"
    ]
 }
  ]
} 

Documentation Feedback

Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.