BaşlayınÜcretsiz başlayın

Name the layer that refused

An engineer has an open ticket: the reports role needs to create an IAM user for a one-off migration. They added iam:CreateUser to the role's own policy an hour ago. The call still fails.

Open the Boundary effect console. Tick iam:CreateUser on the identity policy, then work through the three boundaries the account attaches to new roles and watch the Effective column.

On two of the three, the identity policy allows the action and the call is still refused.

Which layer is doing the refusing?

Bu egzersiz, kursun bir parçasıdır

Using AWS Security for Developers

Kursa Göz Atın

Uygulamalı etkileşimli egzersiz

Teoriyi etkileşime dönüştürün, interaktif egzersizlerimizden biriyle

Egzersize başla