An error occurred (UnauthorizedOperation): You are not authorized to perform this operation. Encoded authorization failure message: ...
The IAM identity is missing an EC2 (or related) permission. The encoded message tells you exactly which action and resource were denied.
Seen on:
AWS
Meaning
EC2 hides the details in an encoded string. Decode it with sts decode-authorization-message (that also needs permission) to see the action, resource and which policy (identity, SCP, permission boundary) denied it.
Common causes
- IAM policy lacks the ec2:* action
- Explicit Deny in an SCP or permission boundary
- Condition (region, tag, MFA) not met
- Using a different role/profile than expected
⚡ Quick fix
- Decode the message to see the denied action
- Add the action to the role’s policy (least privilege)
- Check SCPs/boundaries if the policy looks right
Detailed fix by platform
AWS CLI
aws sts decode-authorization-message --encoded-message "$MSG" --query DecodedMessage --output text | jq .
How to diagnose
- Identity — aws sts get-caller-identity
- Action — From the decoded message
- Deny source — Identity policy, SCP, boundary, condition
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- AccessDenied AWS S3: AccessDenied (403) when calling GetObject / PutObject
- IAM AccessDeniedException AccessDeniedException: User: arn:aws:iam::... is not authorized to perform: service:Action on resource: ...
- Instance reachability check failed EC2 status check failed: Instance reachability check failed (1/2 checks passed)
Most viewed in AWS
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026