AccessDeniedException: User: arn:aws:iam::... is not authorized to perform: service:Action on resource: ...
The IAM user or role making the call has no permission for that action on that resource — the message names both.
Seen on:
AWS
Meaning
The error is precise: the principal ARN, the action (e.g. dynamodb:PutItem, logs:CreateLogGroup) and the resource. Add exactly that to the role’s policy. If it says “with an explicit deny”, an SCP, permission boundary or resource policy blocks it.
Common causes
- Role policy missing the action/resource
- Lambda/ECS execution role lacks permissions (logs, secrets)
- Explicit deny in SCP, boundary or resource policy
- Resource ARN in the policy doesn’t match (wildcard, region, account)
⚡ Quick fix
- Copy the action and resource from the message into the role’s policy
- Simulate: aws iam simulate-principal-policy
- For “explicit deny”, check SCPs and resource policies
Detailed fix by platform
AWS CLI
aws iam simulate-principal-policy --policy-source-arn arn:aws:iam::123456789012:role/app-role --action-names dynamodb:PutItem --resource-arns arn:aws:dynamodb:eu-west-1:123456789012:table/orders
IAM
{ "Effect": "Allow", "Action": ["dynamodb:PutItem"], "Resource": "arn:aws:dynamodb:eu-west-1:123456789012:table/orders" }
How to diagnose
- Principal — Which role is calling?
- Action/resource — From the message
- Deny — "explicit deny" wording?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in AWS
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026