AWS IAM Increases Default Managed Policies Per Role to 20
AWS Identity and Access Management (IAM) has raised the default quota for managed policies per role from 10 to 20. This change aims to simplify adherence to IAM best practices, such as granular permissions, and streamline the integration of AWS Partner products. Users can request a further increase up to 25 via Service Quotas if needed. The update is automatically applied to all IAM roles across all commercial, GovCloud (US), and China AWS Regions without requiring user action.
Enhancements (1) ›
- Increased Default Managed Policies Per IAM Role
The default quota for managed policies attached to an IAM role has been doubled from 10 to 20. This enhancement reduces the need for manual Service Quota requests, particularly when implementing IAM best practices or integrating third-party AWS Partner solutions. A maximum of 25 managed policies per role can be requested through Service Quotas.
https://aws.amazon.com/about-aws/whats-new/2026/08/aws-iam-quota-increase/
Related releases
- AWS Lambda functions now support full IAM resource-based policies AWS What's New ·
- Amazon EKS now supports multiple external OIDC identity providers per cluster AWS What's New ·
- Amazon DynamoDB Streams now supports attribute-based access control (ABAC) AWS What's New ·
- AWS Partner Central agents MCP Server now supports OAuth with AWS Sign-In AWS What's New ·
- AWS details external web access for Amazon Bedrock's Web Search AWS What's New ·
- Amazon CloudWatch Log Centralization Now Supports Log Group Tag Propagation AWS What's New ·