{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "SecurityAdmin",
"Effect": "Allow",
"Action": [
"acm-pca:*",
"macie2:*",
"kms:*",
"tag:*",
"acm:*",
"inspector:*",
"secretsmanager:*",
"securityhub:*",
"securitylake:*",
"cloudhsm:*",
"access-analyzer:*",
"verified-access:*",
"athena:*",
"cloudtrail:*",
"logs:*",
"cloudtrail-data:*",
"config:*",
"detective:*",
"guardduty:*",
"pca-connector-ad:*",
"rolesanywhere:*",
"sso-directory:*",
"sso:*",
"lakeformation:*",
"events:*",
"ssm:*",
"lambda:*",
"inspector2:*",
"shield:*",
"waf:*",
"waf-regional:*",
"wafv2:*",
"network-firewall:*",
"fms:*",
"controltower:*",
"ds:DescribeDirectories",
"ds:AuthorizeApplication",
"ds:UnauthorizeApplication",
"ds:DescribeTrusts",
"organizations:EnableAWSServiceAccess",
"organizations:DescribeOrganization",
"organizations:DescribeAccount",
"organizations:ListRoots",
"organizations:ListAccounts",
"organizations:ListAccountsForParent",
"organizations:ListParents",
"organizations:ListChildren",
"organizations:ListOrganizationalUnitsForParent",
"organizations:ListDelegatedAdministrators",
"identitystore:*",
"identitystore-auth:*",
"ds:CreateAlias",
"access-analyzer:ValidatePolicy"
],
"Resource": "*"
},
{
"Sid": "AWSSSOManageDelegatedAdministrator",
"Effect": "Allow",
"Action": [
"organizations:RegisterDelegatedAdministrator",
"organizations:DeregisterDelegatedAdministrator"
],
"Resource": "*",
"Condition": {
"StringEquals": {
"organizations:ServicePrincipal": "sso.amazonaws.com"
}
}
}
]
}