Amazon S3 adds additional policy details to access denied error messages

Amazon S3 Access Denied Error Messages Update
Amazon S3 now includes the specific IAM and AWS Organizations policy ARN in HTTP 403 Access Denied error messages for same-account and same-organization requests. This helps you quickly identify the exact policy responsible for a denied request and remediate the issue directly.
Previously, S3 access denied error messages included the policy type and reason for denial, but when multiple policies of the same type existed, you still had to manually inspect each one to pinpoint the root cause. Now the error message includes the specific policy ARN for explicit deny cases, covering Service Control Policies (SCPs), Resource Control Policies (RCPs), identity-based policies, session policies, and permission boundaries.
This capability is available in all AWS Regions, including the AWS GovCloud (US) Regions and the AWS China Regions.
What to do
- Review the updated error messages to identify the exact policy causing access denials.
- Remediate the issue by adjusting the specific policy identified in the error message.
- Consult the S3 User Guide and the IAM troubleshooting documentation for further assistance.
Source: AWS release notes
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



