IAM Policies
Permissions Priorities
Deny, Allow, Deny
You start off with no permissions. Access is granted with an Allow statement. An explicit Deny is always denied.
Permissions Boundaries
Permission boundaries don't grant access on thier own. They define the maximum permissions and identity can recieve. Any permissions granted outside of a permissions boundary have no effect.
Policy Evaluation Logic
- Explicit Deny
- Service Control Policy
- Resource Policy
- Permissions Boundary
- Session Policy
- Identity Policy