|
24 | 24 | "Sid": "DenyRoot", |
25 | 25 | "Effect": "Deny", |
26 | 26 | "NotAction": [ |
27 | | - "iam:CreateVirtualMFADevice", |
28 | | - "iam:EnableMFADevice", |
29 | | - "iam:GetUser", |
30 | | - "iam:ListMFADevices", |
31 | | - "iam:ListVirtualMFADevices", |
32 | | - "iam:ResyncMFADevice", |
33 | | - "sts:GetSessionToken" |
| 27 | + "iam:CreateVirtualMFADevice", |
| 28 | + "iam:EnableMFADevice", |
| 29 | + "iam:GetUser", |
| 30 | + "iam:ListMFADevices", |
| 31 | + "iam:ListVirtualMFADevices", |
| 32 | + "iam:ResyncMFADevice", |
| 33 | + "sts:GetSessionToken" |
34 | 34 | ], |
35 | 35 | "Resource": "*", |
36 | 36 | "Condition": { |
|
119 | 119 | "guardduty:UpdateDetector", |
120 | 120 | "guardduty:UpdateFindingsFeedback", |
121 | 121 | "guardduty:UpdatePublishingDestination", |
| 122 | + "guardduty:UpdateOrganizationConfiguration", |
| 123 | + "guardduty:DisableOrganizationAdminAccount", |
122 | 124 | "guardduty:CreateMembers", |
123 | 125 | "guardduty:InviteMembers", |
124 | 126 | "securityhub:AcceptInvitation", |
|
133 | 135 | "securityhub:DisassociateMembers", |
134 | 136 | "securityhub:DeleteActionTarget", |
135 | 137 | "securityhub:BatchDisableStandards", |
| 138 | + "securityhub:UpdateSecurityHubConfiguration", |
| 139 | + "securityhub:UpdateStandardsControl", |
| 140 | + "macie2:AcceptInvitation", |
| 141 | + "macie2:CreateInvitations", |
| 142 | + "macie2:CreateMember", |
| 143 | + "macie2:DeclineInvitations", |
| 144 | + "macie2:DeleteInvitations", |
| 145 | + "macie2:DeleteMember", |
| 146 | + "macie2:DisableMacie", |
| 147 | + "macie2:DisableOrganizationAdminAccount", |
| 148 | + "macie2:DisassociateFromMasterAccount", |
| 149 | + "macie2:DisassociateMember", |
| 150 | + "macie2:EnableMacie", |
| 151 | + "macie2:EnableOrganizationAdminAccount", |
| 152 | + "macie2:UpdateMacieSession", |
| 153 | + "macie2:UpdateMemberSession", |
| 154 | + "macie2:UpdateOrganizationConfiguration", |
136 | 155 | "fms:DisassociateAdminAccount", |
137 | 156 | "access-analyzer:DeleteAnalyzer", |
138 | 157 | "account:EnableRegion", |
|
0 commit comments