UnauthorizedOperation ☁️ AWS

An error occurred (UnauthorizedOperation): You are not authorized to perform this operation. Encoded authorization failure message: ...

The IAM identity is missing an EC2 (or related) permission. The encoded message tells you exactly which action and resource were denied.

Seen on: AWS

Meaning

EC2 hides the details in an encoded string. Decode it with sts decode-authorization-message (that also needs permission) to see the action, resource and which policy (identity, SCP, permission boundary) denied it.

Common causes

  • IAM policy lacks the ec2:* action
  • Explicit Deny in an SCP or permission boundary
  • Condition (region, tag, MFA) not met
  • Using a different role/profile than expected

⚡ Quick fix

  1. Decode the message to see the denied action
  2. Add the action to the role’s policy (least privilege)
  3. Check SCPs/boundaries if the policy looks right

Detailed fix by platform

AWS CLI

  1. aws sts decode-authorization-message --encoded-message "$MSG" --query DecodedMessage --output text | jq .

How to diagnose

  1. Identity — aws sts get-caller-identity
  2. Action — From the decoded message
  3. Deny source — Identity policy, SCP, boundary, condition

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.