aws-iam-policy-types
Version:
Autogenerated Typescript types for AWS IAM Policy and enums for all policy actions
802 lines (801 loc) • 37 kB
TypeScript
/**
* All IAM policy actions for AWS IAM Identity Center (successor to AWS Single Sign-On) (SSO)
*
* Extracted by `aws-iam-policy` from
* https://docs.aws.amazon.com/service-authorization/latest/reference/list_awsiamidentitycentersuccessortoawssinglesign-on.html
*
* 2025-02-24T21:48:13.281Z
*/
export declare enum AwsSsoActions {
/**
* Grants permission to connect a directory to be used by AWS IAM Identity Center
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
AssociateDirectory = "sso:AssociateDirectory",
/**
* Grants permission to create an association between a directory user or group an
* d a profile
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
AssociateProfile = "sso:AssociateProfile",
/**
* Grants permission to attach a customer managed policy reference to a permission
* set
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_AttachCustomerManagedPolicyReferenceToPermissionSet.html
*/
AttachCustomerManagedPolicyReferenceToPermissionSet = "sso:AttachCustomerManagedPolicyReferenceToPermissionSet",
/**
* Grants permission to attach an AWS managed policy to a permission set
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_AttachManagedPolicyToPermissionSet.html
*/
AttachManagedPolicyToPermissionSet = "sso:AttachManagedPolicyToPermissionSet",
/**
* Grants permission to assign access to a Principal for a specified AWS account u
* sing a specified permission set
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_CreateAccountAssignment.html
*/
CreateAccountAssignment = "sso:CreateAccountAssignment",
/**
* Grants permission to create an application
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_CreateApplication.html
*/
CreateApplication = "sso:CreateApplication",
/**
* Grants permission to create an application assignment
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_CreateApplicationAssignment.html
*/
CreateApplicationAssignment = "sso:CreateApplicationAssignment",
/**
* Grants permission to add an application instance to AWS IAM Identity Center
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
CreateApplicationInstance = "sso:CreateApplicationInstance",
/**
* Grants permission to add a new certificate for an application instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
CreateApplicationInstanceCertificate = "sso:CreateApplicationInstanceCertificate",
/**
* Grants permission to create an identity center instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_CreateInstance.html
*/
CreateInstance = "sso:CreateInstance",
/**
* Grants permission to enable the instance for ABAC and specify the attributes
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_CreateInstanceAccessControlAttributeConfiguration.html
*/
CreateInstanceAccessControlAttributeConfiguration = "sso:CreateInstanceAccessControlAttributeConfiguration",
/**
* Grants permission to add a managed application instance to AWS IAM Identity Cen
* ter
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
CreateManagedApplicationInstance = "sso:CreateManagedApplicationInstance",
/**
* Grants permission to create a permission set
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_CreatePermissionSet.html
*/
CreatePermissionSet = "sso:CreatePermissionSet",
/**
* Grants permission to create a profile for an application instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
CreateProfile = "sso:CreateProfile",
/**
* Grants permission to create a federation trust in a target account
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
CreateTrust = "sso:CreateTrust",
/**
* Grants permission to create a trusted token issuer for an instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_CreateTrustedTokenIssuer.html
*/
CreateTrustedTokenIssuer = "sso:CreateTrustedTokenIssuer",
/**
* Grants permission to delete a Principal's access from a specified AWS account u
* sing a specified permission set
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeleteAccountAssignment.html
*/
DeleteAccountAssignment = "sso:DeleteAccountAssignment",
/**
* Grants permission to delete an application
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeleteApplication.html
*/
DeleteApplication = "sso:DeleteApplication",
/**
* Grants permission to delete an access scope to an application
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeleteApplicationAccessScope.html
*/
DeleteApplicationAccessScope = "sso:DeleteApplicationAccessScope",
/**
* Grants permission to delete an application assignment
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeleteApplicationAssignment.html
*/
DeleteApplicationAssignment = "sso:DeleteApplicationAssignment",
/**
* Grants permission to delete an authentication method to an application
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeleteApplicationAuthenticationMethod.html
*/
DeleteApplicationAuthenticationMethod = "sso:DeleteApplicationAuthenticationMethod",
/**
* Grants permission to delete a grant from an application
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeleteApplicationGrant.html
*/
DeleteApplicationGrant = "sso:DeleteApplicationGrant",
/**
* Grants permission to delete the application instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
DeleteApplicationInstance = "sso:DeleteApplicationInstance",
/**
* Grants permission to delete an inactive or expired certificate from the applica
* tion instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
DeleteApplicationInstanceCertificate = "sso:DeleteApplicationInstanceCertificate",
/**
* Grants permission to delete the inline policy from a specified permission set
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeleteInlinePolicyFromPermissionSet.html
*/
DeleteInlinePolicyFromPermissionSet = "sso:DeleteInlinePolicyFromPermissionSet",
/**
* Grants permission to delete an identity center instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeleteInstance.html
*/
DeleteInstance = "sso:DeleteInstance",
/**
* Grants permission to disable ABAC and remove the attributes list for the instan
* ce
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeleteInstanceAccessControlAttributeConfiguration.html
*/
DeleteInstanceAccessControlAttributeConfiguration = "sso:DeleteInstanceAccessControlAttributeConfiguration",
/**
* Grants permission to delete the managed application instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
DeleteManagedApplicationInstance = "sso:DeleteManagedApplicationInstance",
/**
* Grants permission to delete a permission set
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeletePermissionSet.html
*/
DeletePermissionSet = "sso:DeletePermissionSet",
/**
* Grants permission to remove permissions boundary from a permission set
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeletePermissionsBoundaryFromPermissionSet.html
*/
DeletePermissionsBoundaryFromPermissionSet = "sso:DeletePermissionsBoundaryFromPermissionSet",
/**
* Grants permission to delete the permission policy associated with a permission
* set
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
DeletePermissionsPolicy = "sso:DeletePermissionsPolicy",
/**
* Grants permission to delete the profile for an application instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
DeleteProfile = "sso:DeleteProfile",
/**
* Grants permission to delete a trusted token issuer for an instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeleteTrustedTokenIssuer.html
*/
DeleteTrustedTokenIssuer = "sso:DeleteTrustedTokenIssuer",
/**
* Grants permission to describe the status of the assignment creation request
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DescribeAccountAssignmentCreationStatus.html
*/
DescribeAccountAssignmentCreationStatus = "sso:DescribeAccountAssignmentCreationStatus",
/**
* Grants permission to describe the status of an assignment deletion request
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DescribeAccountAssignmentDeletionStatus.html
*/
DescribeAccountAssignmentDeletionStatus = "sso:DescribeAccountAssignmentDeletionStatus",
/**
* Grants permission to obtain information about an application
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DescribeApplication.html
*/
DescribeApplication = "sso:DescribeApplication",
/**
* Grants permission to retrieve an application assignment
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DescribeApplicationAssignment.html
*/
DescribeApplicationAssignment = "sso:DescribeApplicationAssignment",
/**
* Grants permission to describe an application provider
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DescribeApplicationProvider.html
*/
DescribeApplicationProvider = "sso:DescribeApplicationProvider",
/**
* Grants permission to obtain information about the directories for this account
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
DescribeDirectories = "sso:DescribeDirectories",
/**
* Grants permission to obtain information about an identity center instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DescribeInstance.html
*/
DescribeInstance = "sso:DescribeInstance",
/**
* Grants permission to get the list of attributes used by the instance for ABAC
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DescribeInstanceAccessControlAttributeConfiguration.html
*/
DescribeInstanceAccessControlAttributeConfiguration = "sso:DescribeInstanceAccessControlAttributeConfiguration",
/**
* Grants permission to describe a permission set
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DescribePermissionSet.html
*/
DescribePermissionSet = "sso:DescribePermissionSet",
/**
* Grants permission to describe the status for the given Permission Set Provision
* ing request
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DescribePermissionSetProvisioningStatus.html
*/
DescribePermissionSetProvisioningStatus = "sso:DescribePermissionSetProvisioningStatus",
/**
* Grants permission to retrieve all the permissions policies associated with a pe
* rmission set
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
DescribePermissionsPolicies = "sso:DescribePermissionsPolicies",
/**
* Grants permission to obtain the regions where your organization has enabled AWS
* IAM Identity Center
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
DescribeRegisteredRegions = "sso:DescribeRegisteredRegions",
/**
* Grants permission to describe a trusted token issuer for an instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DescribeTrustedTokenIssuer.html
*/
DescribeTrustedTokenIssuer = "sso:DescribeTrustedTokenIssuer",
/**
* Grants permission to obtain information about the trust relationships for this
* account
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
DescribeTrusts = "sso:DescribeTrusts",
/**
* Grants permission to detach a customer managed policy reference from a permissi
* on set
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DetachCustomerManagedPolicyReferenceFromPermissionSet.html
*/
DetachCustomerManagedPolicyReferenceFromPermissionSet = "sso:DetachCustomerManagedPolicyReferenceFromPermissionSet",
/**
* Grants permission to detach the attached AWS managed policy from the specified
* permission set
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DetachManagedPolicyFromPermissionSet.html
*/
DetachManagedPolicyFromPermissionSet = "sso:DetachManagedPolicyFromPermissionSet",
/**
* Grants permission to disassociate a directory to be used by AWS IAM Identity Ce
* nter
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
DisassociateDirectory = "sso:DisassociateDirectory",
/**
* Grants permission to disassociate a directory user or group from a profile
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
DisassociateProfile = "sso:DisassociateProfile",
/**
* Grants permission to get an access scope to an application
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_GetApplicationAccessScope.html
*/
GetApplicationAccessScope = "sso:GetApplicationAccessScope",
/**
* Grants permission to read assignment configurations for an application
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_GetApplicationAssignmentConfiguration.html
*/
GetApplicationAssignmentConfiguration = "sso:GetApplicationAssignmentConfiguration",
/**
* Grants permission to get an authentication method to an application
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_GetApplicationAuthenticationMethod.html
*/
GetApplicationAuthenticationMethod = "sso:GetApplicationAuthenticationMethod",
/**
* Grants permission to obtain details about a grant belonging to an application
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_GetApplicationGrant.html
*/
GetApplicationGrant = "sso:GetApplicationGrant",
/**
* Grants permission to retrieve details for an application instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
GetApplicationInstance = "sso:GetApplicationInstance",
/**
* Grants permission to retrieve application template details
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
GetApplicationTemplate = "sso:GetApplicationTemplate",
/**
* Grants permission to obtain the inline policy assigned to the permission set
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_GetInlinePolicyForPermissionSet.html
*/
GetInlinePolicyForPermissionSet = "sso:GetInlinePolicyForPermissionSet",
/**
* Grants permission to retrieve details for an application instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
GetManagedApplicationInstance = "sso:GetManagedApplicationInstance",
/**
* Grants permission to retrieve Mfa Device Management settings for the directory
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
GetMfaDeviceManagementForDirectory = "sso:GetMfaDeviceManagementForDirectory",
/**
* Grants permission to retrieve details of a permission set
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
GetPermissionSet = "sso:GetPermissionSet",
/**
* Grants permission to get permissions boundary for a permission set
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_GetPermissionsBoundaryForPermissionSet.html
*/
GetPermissionsBoundaryForPermissionSet = "sso:GetPermissionsBoundaryForPermissionSet",
/**
* Grants permission to retrieve all permission policies associated with a permiss
* ion set
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
GetPermissionsPolicy = "sso:GetPermissionsPolicy",
/**
* Grants permission to retrieve a profile for an application instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
GetProfile = "sso:GetProfile",
/**
* Grants permission to check if AWS IAM Identity Center is enabled
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
GetSSOStatus = "sso:GetSSOStatus",
/**
* Grants permission to retrieve shared configuration for the current SSO instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
GetSharedSsoConfiguration = "sso:GetSharedSsoConfiguration",
/**
* Grants permission to retrieve configuration for the current SSO instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
GetSsoConfiguration = "sso:GetSsoConfiguration",
/**
* Grants permission to retrieve the federation trust in a target account
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
GetTrust = "sso:GetTrust",
/**
* Grants permission to update the application instance by uploading an applicatio
* n SAML metadata file provided by the service provider
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
ImportApplicationInstanceServiceProviderMetadata = "sso:ImportApplicationInstanceServiceProviderMetadata",
/**
* Grants permission to list the status of the AWS account assignment creation req
* uests for a specified SSO instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListAccountAssignmentCreationStatus.html
*/
ListAccountAssignmentCreationStatus = "sso:ListAccountAssignmentCreationStatus",
/**
* Grants permission to list the status of the AWS account assignment deletion req
* uests for a specified SSO instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListAccountAssignmentDeletionStatus.html
*/
ListAccountAssignmentDeletionStatus = "sso:ListAccountAssignmentDeletionStatus",
/**
* Grants permission to list the assignee of the specified AWS account with the sp
* ecified permission set
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListAccountAssignments.html
*/
ListAccountAssignments = "sso:ListAccountAssignments",
/**
* Grants permission to list accounts assigned to user or group
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListAccountAssignmentsForPrincipal.html
*/
ListAccountAssignmentsForPrincipal = "sso:ListAccountAssignmentsForPrincipal",
/**
* Grants permission to list all the AWS accounts where the specified permission s
* et is provisioned
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListAccountsForProvisionedPermissionSet.html
*/
ListAccountsForProvisionedPermissionSet = "sso:ListAccountsForProvisionedPermissionSet",
/**
* Grants permission to list access scopes to an application
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListApplicationAccessScopes.html
*/
ListApplicationAccessScopes = "sso:ListApplicationAccessScopes",
/**
* Grants permission to list application assignments
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListApplicationAssignments.html
*/
ListApplicationAssignments = "sso:ListApplicationAssignments",
/**
* Grants permission to list applications assigned to user or group
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListApplicationAssignmentsForPrincipal.html
*/
ListApplicationAssignmentsForPrincipal = "sso:ListApplicationAssignmentsForPrincipal",
/**
* Grants permission to list authentication methods to an application
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListApplicationAuthenticationMethods.html
*/
ListApplicationAuthenticationMethods = "sso:ListApplicationAuthenticationMethods",
/**
* Grants permission to list grants from an application
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListApplicationGrants.html
*/
ListApplicationGrants = "sso:ListApplicationGrants",
/**
* Grants permission to retrieve all of the certificates for a given application i
* nstance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
ListApplicationInstanceCertificates = "sso:ListApplicationInstanceCertificates",
/**
* Grants permission to retrieve all application instances
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
ListApplicationInstances = "sso:ListApplicationInstances",
/**
* Grants permission to list application providers
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListApplicationProviders.html
*/
ListApplicationProviders = "sso:ListApplicationProviders",
/**
* Grants permission to retrieve all supported application templates
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
ListApplicationTemplates = "sso:ListApplicationTemplates",
/**
* Grants permission to retrieve all applications associated with the instance of
* IAM Identity Center
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListApplications.html
*/
ListApplications = "sso:ListApplications",
/**
* Grants permission to list the customer managed policy references that are attac
* hed to a permission set
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListCustomerManagedPolicyReferencesInPermissionSet.html
*/
ListCustomerManagedPolicyReferencesInPermissionSet = "sso:ListCustomerManagedPolicyReferencesInPermissionSet",
/**
* Grants permission to retrieve details about the directory connected to AWS IAM
* Identity Center
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
ListDirectoryAssociations = "sso:ListDirectoryAssociations",
/**
* Grants permission to list the SSO Instances that the caller has access to
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListInstances.html
*/
ListInstances = "sso:ListInstances",
/**
* Grants permission to list the AWS managed policies that are attached to a speci
* fied permission set
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListManagedPoliciesInPermissionSet.html
*/
ListManagedPoliciesInPermissionSet = "sso:ListManagedPoliciesInPermissionSet",
/**
* Grants permission to list the status of the Permission Set Provisioning request
* s for a specified SSO instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListPermissionSetProvisioningStatus.html
*/
ListPermissionSetProvisioningStatus = "sso:ListPermissionSetProvisioningStatus",
/**
* Grants permission to retrieve all permission sets
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListPermissionSets.html
*/
ListPermissionSets = "sso:ListPermissionSets",
/**
* Grants permission to list all the permission sets that are provisioned to a spe
* cified AWS account
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListPermissionSetsProvisionedToAccount.html
*/
ListPermissionSetsProvisionedToAccount = "sso:ListPermissionSetsProvisionedToAccount",
/**
* Grants permission to retrieve the directory user or group associated with the p
* rofile
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
ListProfileAssociations = "sso:ListProfileAssociations",
/**
* Grants permission to retrieve all profiles for an application instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
ListProfiles = "sso:ListProfiles",
/**
* Grants permission to list the tags that are attached to a specified resource
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListTagsForResource.html
*/
ListTagsForResource = "sso:ListTagsForResource",
/**
* Grants permission to list trusted token issuers for an instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListTrustedTokenIssuers.html
*/
ListTrustedTokenIssuers = "sso:ListTrustedTokenIssuers",
/**
* Grants permission to provision a specified permission set to the specified targ
* et
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ProvisionPermissionSet.html
*/
ProvisionPermissionSet = "sso:ProvisionPermissionSet",
/**
* Grants permission to create/update an access scope to an application
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_PutApplicationAccessScope.html
*/
PutApplicationAccessScope = "sso:PutApplicationAccessScope",
/**
* Grants permission to add assignment configurations to an application
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_PutApplicationAssignmentConfiguration.html
*/
PutApplicationAssignmentConfiguration = "sso:PutApplicationAssignmentConfiguration",
/**
* Grants permission to create/update an authentication method to an application
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_PutApplicationAuthenticationMethod.html
*/
PutApplicationAuthenticationMethod = "sso:PutApplicationAuthenticationMethod",
/**
* Grants permission to create/update a grant to an application
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_PutApplicationGrant.html
*/
PutApplicationGrant = "sso:PutApplicationGrant",
/**
* Grants permission to attach an IAM inline policy to a permission set
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_PutInlinePolicyToPermissionSet.html
*/
PutInlinePolicyToPermissionSet = "sso:PutInlinePolicyToPermissionSet",
/**
* Grants permission to put Mfa Device Management settings for the directory
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
PutMfaDeviceManagementForDirectory = "sso:PutMfaDeviceManagementForDirectory",
/**
* Grants permission to add permissions boundary to a permission set
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_PutPermissionsBoundaryToPermissionSet.html
*/
PutPermissionsBoundaryToPermissionSet = "sso:PutPermissionsBoundaryToPermissionSet",
/**
* Grants permission to add a policy to a permission set
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
PutPermissionsPolicy = "sso:PutPermissionsPolicy",
/**
* Grants permission to search for groups within the associated directory
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
SearchGroups = "sso:SearchGroups",
/**
* Grants permission to search for users within the associated directory
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
SearchUsers = "sso:SearchUsers",
/**
* Grants permission to initialize AWS IAM Identity Center
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
StartSSO = "sso:StartSSO",
/**
* Grants permission to associate a set of tags with a specified resource
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_TagResource.html
*/
TagResource = "sso:TagResource",
/**
* Grants permission to disassociate a set of tags from a specified resource
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_UntagResource.html
*/
UntagResource = "sso:UntagResource",
/**
* Grants permission to update an application
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_UpdateApplication.html
*/
UpdateApplication = "sso:UpdateApplication",
/**
* Grants permission to set a certificate as the active one for this application i
* nstance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
UpdateApplicationInstanceActiveCertificate = "sso:UpdateApplicationInstanceActiveCertificate",
/**
* Grants permission to update display data of an application instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
UpdateApplicationInstanceDisplayData = "sso:UpdateApplicationInstanceDisplayData",
/**
* Grants permission to update federation response configuration for the applicati
* on instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
UpdateApplicationInstanceResponseConfiguration = "sso:UpdateApplicationInstanceResponseConfiguration",
/**
* Grants permission to update federation response schema configuration for the ap
* plication instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
UpdateApplicationInstanceResponseSchemaConfiguration = "sso:UpdateApplicationInstanceResponseSchemaConfiguration",
/**
* Grants permission to update security details for the application instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
UpdateApplicationInstanceSecurityConfiguration = "sso:UpdateApplicationInstanceSecurityConfiguration",
/**
* Grants permission to update service provider related configuration for the appl
* ication instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
UpdateApplicationInstanceServiceProviderConfiguration = "sso:UpdateApplicationInstanceServiceProviderConfiguration",
/**
* Grants permission to update the status of an application instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
UpdateApplicationInstanceStatus = "sso:UpdateApplicationInstanceStatus",
/**
* Grants permission to update the user attribute mappings for your connected dire
* ctory
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
UpdateDirectoryAssociation = "sso:UpdateDirectoryAssociation",
/**
* Grants permission to update an identity center instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_UpdateInstance.html
*/
UpdateInstance = "sso:UpdateInstance",
/**
* Grants permission to update the attributes to use with the instance for ABAC
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_UpdateInstanceAccessControlAttributeConfiguration.html
*/
UpdateInstanceAccessControlAttributeConfiguration = "sso:UpdateInstanceAccessControlAttributeConfiguration",
/**
* Grants permission to update the status of a managed application instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
UpdateManagedApplicationInstanceStatus = "sso:UpdateManagedApplicationInstanceStatus",
/**
* Grants permission to update the permission set
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_UpdatePermissionSet.html
*/
UpdatePermissionSet = "sso:UpdatePermissionSet",
/**
* Grants permission to update the profile for an application instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
UpdateProfile = "sso:UpdateProfile",
/**
* Grants permission to update the configuration for the current SSO instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
UpdateSSOConfiguration = "sso:UpdateSSOConfiguration",
/**
* Grants permission to update the federation trust in a target account
*
* See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample
*/
UpdateTrust = "sso:UpdateTrust",
/**
* Grants permission to update a trusted token issuer for an instance
*
* See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_UpdateTrustedTokenIssuer.html
*/
UpdateTrustedTokenIssuer = "sso:UpdateTrustedTokenIssuer"
}