AWS IAM Policy Generator
Build an IAM policy from services, actions and resource ARNs with condition keys for MFA, source IP and encryption, and warnings for the wildcards that make a policy permissive by accident.
Last reviewed by the Radiatus Cloud team
Want this automated for your stack?
We build CI/CD, Kubernetes & IaC pipelines that scale.
Wildcards are how least privilege quietly fails
An IAM policy granting s3:* on Resource "*" is one line and grants the ability to read, write, delete and change the permissions of every bucket in the account. Policies reach that state gradually: a permission is missing, the fastest fix is to widen the action, and nobody narrows it afterwards. The IAM Access Analyzer exists precisely because the gap between what a policy grants and what a principal actually uses is usually enormous.
Resource level permissions are not universal
Many actions do not support resource level restriction and must be granted on "*". Listing buckets, describing EC2 instances and most list and describe operations fall into this category. The correct pattern is to split the policy into a statement granting those actions on "*", ideally with a condition, and a second statement granting the resource specific actions on named ARNs. A policy that grants everything on "*" because one action required it is a common and avoidable outcome.
Conditions are where the real control lives
A condition block can require multi factor authentication, restrict access to a source IP range or VPC endpoint, require that uploaded objects are encrypted, or deny anything not using TLS. These are far more effective than trimming action lists, because they constrain the circumstances of use rather than the vocabulary. A deny statement with a condition is also evaluated before any allow, which makes it the reliable way to enforce a boundary that no other policy can override.
Related tools
- CI/CD Security Gap Analyzer — Checklist based analyzer for CI/CD pipeline security gaps.
- Docker Security Scanner — A new tool extracted from the codebase.
- Terraform Scanner — A new tool extracted from the codebase.
- SQL Formatter — Format and indent SQL queries for readability. Handles joins, subqueries and CTEs, supports common dialects, and runs entirely in your browser.
Frequently Asked Questions
Why does my policy need Resource "*" for some actions?
Because many list and describe operations act on the account rather than on a resource and do not support resource level permissions. Split them into their own statement rather than widening the whole policy, and constrain them with a condition where you can.
What is the difference between an identity policy and a resource policy?
An identity policy attaches to a user, group or role and says what that principal may do. A resource policy attaches to the resource, such as a bucket, and says who may act on it. Cross account access requires both sides to allow it.
How do explicit denies work?
An explicit deny always wins, evaluated before any allow, and cannot be overridden by any other policy including an administrator policy. That makes a deny with a condition the reliable way to enforce a boundary such as requiring TLS or blocking a region.
How do I find the permissions actually needed?
IAM Access Analyzer generates a policy from CloudTrail activity over a period, which is far more accurate than reasoning from documentation. Start permissive in a development account, capture real usage, then generate and apply the narrow policy.
What does NotAction do and should I use it?
It matches everything except the listed actions, which means every new service AWS launches is automatically included. It is occasionally correct in a deny statement and almost always wrong in an allow, where it grants permissions that did not exist when the policy was written.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Choose a service and access level, set the resource ARNs, and copy the generated policy JSON.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.