AWS Identity Store
(identitystore)
IAM Changes
Services
2025-11-22
2025-11-22
5 new conditions | 19 updated actions
Additions
Conditions
identitystore:GroupExternalIdIssuers
Description:
Filters access by Issuer present in ExternalIds for Group resources
Type:
ArrayOfARN
identitystore:IdentityStoreArn
Description:
Filters access by Identity Store ARN
Type:
ARN
identitystore:PrimaryRegion
Description:
Filters access by Primary Region of Identity Store
Type:
String
identitystore:ReservedUserId
Description:
Filters access by a previously reserved User ID for CreateUser operation
Type:
String
identitystore:UserExternalIdIssuers
Description:
Filters access by Issuer present in ExternalIds for User resources
Type:
ArrayOfARN
Updates
Actions
CreateGroup
Conditions
+ identitystore:PrimaryRegion
+ identitystore:GroupExternalIdIssuers
CreateGroupMembership
Conditions
+ identitystore:PrimaryRegion
CreateUser
Conditions
+ identitystore:PrimaryRegion
+ identitystore:UserExternalIdIssuers
+ identitystore:ReservedUserId
DeleteGroup
Conditions
+ identitystore:PrimaryRegion
+ identitystore:GroupExternalIdIssuers
DeleteGroupMembership
Conditions
+ identitystore:PrimaryRegion
DeleteUser
Conditions
+ identitystore:PrimaryRegion
+ identitystore:UserExternalIdIssuers
DescribeGroup
Conditions
+ identitystore:PrimaryRegion
+ identitystore:GroupExternalIdIssuers
DescribeGroupMembership
Conditions
+ identitystore:PrimaryRegion
DescribeUser
Conditions
+ identitystore:PrimaryRegion
+ identitystore:UserExternalIdIssuers
GetGroupId
Conditions
+ identitystore:PrimaryRegion
GetGroupMembershipId
Conditions
+ identitystore:PrimaryRegion
GetUserId
Conditions
+ identitystore:PrimaryRegion
IsMemberInGroups
Conditions
+ identitystore:PrimaryRegion
ListGroupMemberships
Conditions
+ identitystore:PrimaryRegion
ListGroupMembershipsForMember
Conditions
+ identitystore:PrimaryRegion
ListGroups
Conditions
+ identitystore:PrimaryRegion
+ identitystore:GroupExternalIdIssuers
ListUsers
Conditions
+ identitystore:PrimaryRegion
+ identitystore:UserExternalIdIssuers
UpdateGroup
Conditions
+ identitystore:PrimaryRegion
+ identitystore:GroupExternalIdIssuers
UpdateUser
Conditions
+ identitystore:PrimaryRegion
+ identitystore:UserExternalIdIssuers