setting up IAM User regional control (IAM Permission boundary)

Photo by Jan Canty on Unsplash

setting up IAM User regional control (IAM Permission boundary)

AWS/AWS Identity and Access Management

  • outline

There are several ways to control IAM Users by region by applying the information covered in "", but the simplest way is to set an IAM permission boundary.

  • policy
    "Version": "2012-10-17",
    "Statement": [
            "Effect": "Allow",
            "Action": [
            "Resource": "*",
            "Condition": {
                "StringEquals": {
                    "aws:RequestedRegion": [
            "Effect": "Allow",
            "Action": "*",
            "Resource": "*",
            "Condition": {
                "StringEquals": {
                    "aws:RequestedRegion": [
  • how-to-set-up

choose IAM User
\>> Permissions
\>>> Permission boundary, Set permission boundary
\>>>> choose Permissions policies above
\>>>>> Set boundary

  • note

Using example policy from "", you can only use ap-northeast-1 region.

  • reference