Concept and mechanism
An identity determines who makes a request; policies determine which actions it may perform on which resources. For EC2 workloads, a role avoids storing permanent keys in the application. For people, federation and temporary credentials connect access to identity lifecycle. When assuming a role across accounts, distinguish trust in the principal allowed to assume it from permissions granted to the resulting session. An SCP limits permissions in covered member accounts; it does not grant access itself. An applicable explicit Deny overrides an Allow even if the Allow is more specific.
Guided application
During an AccessDenied incident, record principal, action, resource, and request context. Analyze identity policies, resource policies, and applicable limits before changing permissions. For KMS-encrypted data, permission to read the object does not prove that the key permits the required operation. The key policy controls key access and may delegate use of IAM policies. Remediation should restrict actions and resources to the required flow, receive approval when central controls are affected, and include positive and negative tests.
The role can read reconciliation/*, but the KMS key does not authorize its session. Opening the bucket to everyone does not fix key authorization and introduces another risk.
Common pitfalls
Confusing trust with service permissions; using permanent keys to bypass an error; treating an SCP as an access grant.
Related topics: Networks, endpoints, and hybrid connectivity · Data protection and recovery
Identify the layer denying the request and correct the minimum necessary.
Reference: IAM security best practices · SAA-C03