AWS introduces additional policy details to access denied error messages

Published
January 21, 2026
https://aws.amazon.com/about-aws/whats-new/2026/01/additional-policy-details-access-denied-error/

AWS IAM and Organizations Policy ARN in Access Denied Errors

AWS now includes the IAM and Organizations policy’s Amazon Resource Name (ARN) in access denied error messages in same account and same organization scenarios. This allows you to quickly identify the exact policy responsible for the denied access and take action to troubleshoot the issue.

What to do

  • Review access denied error messages for the new ARN information.
  • Identify and address the specific policy causing the access denial.

This additional context will gradually become available across AWS services in all AWS regions. To learn more, refer to IAM documentation.




If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.

Follow our blog

Get the latest insights and advice on AWS services from our experts.

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.