IAM Policy Simulator integrated into IAM console with new features
AWS IAM Policy Simulator has been integrated into the IAM console, replacing the standalone tool and adding capabilities to test Service Control Policies (SCPs) and condition keys. The update allows for more flexible scenario modeling, including policy exclusion and detailed cross-account decision reporting. These enhancements aim to improve policy validation and automation for security and platform teams, and are available in all regions where the simulator is offered.
- →Support for testing Service Control Policies (SCPs)
- →Enhanced simulation flexibility with condition keys and policy exclusion
- →IAM Policy Simulator integrated into IAM console
- →Improved cross-account simulation reporting
- →Availability and access
Features (2) ›
- Support for testing Service Control Policies (SCPs)
Users can now include SCPs in simulations to evaluate the interaction between organizational SCP hierarchies and identity/resource policies.
- Enhanced simulation flexibility with condition keys and policy exclusion
The simulator supports testing with condition keys like region restrictions and tag requirements via the API. It also allows users to exclude specific policies to model 'what if I remove this policy?' scenarios.
Enhancements (2) ›
- IAM Policy Simulator integrated into IAM console
The IAM Policy Simulator is now part of the IAM console, providing a unified location for policy management and testing. This replaces the previous standalone simulator site.
- Improved cross-account simulation reporting
Cross-account simulations now provide per-policy decisions for identity and resource-based policies, returning only the matched statements that led to a denied request.
Notes (1) ›
- Availability and access
These new features are available in all AWS Regions where IAM Policy Simulator is supported. Access is through the 'Policy simulator' option in the IAM console navigation pane.
https://aws.amazon.com/about-aws/whats-new/2026/07/iam-policy-simulator-iam-console/
Related releases
- SageMaker Unified Studio Enhances Git Version Control Across Project Tools AWS What's New ·
- AWS IAM Identity Center adds multi-Region replication for its own directory AWS What's New ·
- Amazon EKS supports AWS PrivateLink for OIDC endpoint AWS What's New ·
- Amazon Neptune adds IAM tag-based access control for data plane operations AWS What's New ·
- Amazon Bedrock AgentCore enables unified observability for AI agents AWS What's New ·
- AWS CloudTrail enhances network activity event filtering by IAM identity AWS What's New ·