AWS IAM now provides role manager to set up IAM roles automatically

Published
August 12, 2026
https://aws.amazon.com/about-aws/whats-new/2026/08/aws-iam-role-manager

AWS IAM Role Manager Now Generally Available

AWS announces the general availability of role manager, a capability in AWS Identity and Access Management (IAM) that automatically sets up the IAM roles your AWS services need. When you set up a supported service in the console, role manager creates a default role on your behalf, or reuses one that already exists in your account if it already matches the required permissions. You can enable or disable role manager at any time, as well as inspect the AWS-managed templates that role manager deploys on your behalf.

Role manager supports 6 AWS service consoles at launch, including AWS Lambda and Amazon EventBridge. Roles created via role manager appear in the IAM console as standard IAM roles that you fully control, and you can identify the ones role manager created. When you are ready to tighten permissions, you can disable role manager and use IAM Access Analyzer to refine each role to only the permissions it needs.

What to do

  • Enable or disable role manager as needed.
  • Inspect AWS-managed templates deployed by role manager.
  • Use IAM Access Analyzer to refine roles when ready.

Role manager is available in all AWS Regions, except the AWS GovCloud (US) Regions and the China Regions.

Source: AWS release notes




If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.

Follow our blog

Get the latest insights and advice on AWS services from our experts.

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.