IAM AccessDeniedException ☁️ AWS

AccessDeniedException: User: arn:aws:iam::... is not authorized to perform: service:Action on resource: ...

The IAM user or role making the call has no permission for that action on that resource — the message names both.

Seen on: AWS

Meaning

The error is precise: the principal ARN, the action (e.g. dynamodb:PutItem, logs:CreateLogGroup) and the resource. Add exactly that to the role’s policy. If it says “with an explicit deny”, an SCP, permission boundary or resource policy blocks it.

Common causes

  • Role policy missing the action/resource
  • Lambda/ECS execution role lacks permissions (logs, secrets)
  • Explicit deny in SCP, boundary or resource policy
  • Resource ARN in the policy doesn’t match (wildcard, region, account)

⚡ Quick fix

  1. Copy the action and resource from the message into the role’s policy
  2. Simulate: aws iam simulate-principal-policy
  3. For “explicit deny”, check SCPs and resource policies

Detailed fix by platform

AWS CLI

  1. aws iam simulate-principal-policy --policy-source-arn arn:aws:iam::123456789012:role/app-role --action-names dynamodb:PutItem --resource-arns arn:aws:dynamodb:eu-west-1:123456789012:table/orders

IAM

  1. { "Effect": "Allow", "Action": ["dynamodb:PutItem"], "Resource": "arn:aws:dynamodb:eu-west-1:123456789012:table/orders" }

How to diagnose

  1. Principal — Which role is calling?
  2. Action/resource — From the message
  3. Deny — "explicit deny" wording?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.