aws AWS What's New ·

Amazon S3 enhances access denied errors with specific policy ARNs

securityawsgaengineeraws-s3aws-iam
feature

Amazon S3 now provides specific AWS IAM and AWS Organizations policy Amazon Resource Names (ARNs) directly within HTTP 403 Access Denied error messages. This enhancement helps users quickly pinpoint the exact policy causing a denied request, streamlining troubleshooting, especially when multiple policies of the same type are in effect. It applies to same-account and same-organization requests, covering various policy types including SCPs, RCPs, identity-based, session, and permission boundaries. This capability is available across all AWS Regions, including GovCloud and China Regions.

Features (1)
  • S3 Access Denied errors now show policy ARNs

    Amazon S3 now includes the specific AWS Identity and Access Management (IAM) and AWS Organizations policy ARN in HTTP 403 Access Denied error messages for same-account and same-organization requests. This helps quickly identify the exact policy responsible for a denied request and remediate the issue directly, covering Service Control Policies (SCPs), Resource Control Policies (RCPs), identity-based policies, session policies, and permission boundaries.

Read the original announcement →

https://aws.amazon.com/about-aws/whats-new/2026/08/s3-additional-policy-details-access-denied-error-messages/

Related releases