IAM Policy Simulator integrated into IAM console with new features
AWS IAM Policy Simulator has been integrated into the IAM console, replacing the standalone tool and adding capabilities to test Service Control Policies (SCPs) and condition keys. The update allows for more flexible scenario modeling, including policy exclusion and detailed cross-account decision reporting. These enhancements aim to improve policy validation and automation for security and platform teams, and are available in all regions where the simulator is offered.
- →Support for testing Service Control Policies (SCPs)
- →Enhanced simulation flexibility with condition keys and policy exclusion
- →IAM Policy Simulator integrated into IAM console
- →Improved cross-account simulation reporting
- →Availability and access
Features (2) ›
- Support for testing Service Control Policies (SCPs)
Users can now include SCPs in simulations to evaluate the interaction between organizational SCP hierarchies and identity/resource policies.
- Enhanced simulation flexibility with condition keys and policy exclusion
The simulator supports testing with condition keys like region restrictions and tag requirements via the API. It also allows users to exclude specific policies to model 'what if I remove this policy?' scenarios.
Enhancements (2) ›
- IAM Policy Simulator integrated into IAM console
The IAM Policy Simulator is now part of the IAM console, providing a unified location for policy management and testing. This replaces the previous standalone simulator site.
- Improved cross-account simulation reporting
Cross-account simulations now provide per-policy decisions for identity and resource-based policies, returning only the matched statements that led to a denied request.
Notes (1) ›
- Availability and access
These new features are available in all AWS Regions where IAM Policy Simulator is supported. Access is through the 'Policy simulator' option in the IAM console navigation pane.
https://aws.amazon.com/about-aws/whats-new/2026/07/iam-policy-simulator-iam-console/
Related releases
- Amazon ECS expands IAM condition key support for RunTask and StartTask APIs AWS What's New ·
- Terraform AWS Provider v6.64.0 Adds New Resources and Bedrock Agent Enhancements Terraform AWS Provider Releases ·
- AWS Systems Manager Enhances Diagnosis for Unmanaged EC2 Instances AWS What's New ·
- Amazon S3 Object Lock now supports variable retention with event holds AWS What's New ·
- SageMaker Unified Studio CI/CD adds notebook promotion and AI-assisted manifest generation AWS What's New ·
- AWS Details Managing IAM Identity Center Identity Source Transitions AWS Security Blog ·