UNPKG

aws-iam-policy-types

Version:

Autogenerated Typescript types for AWS IAM Policy and enums for all policy actions

802 lines (801 loc) 37 kB
/** * All IAM policy actions for AWS IAM Identity Center (successor to AWS Single Sign-On) (SSO) * * Extracted by `aws-iam-policy` from * https://docs.aws.amazon.com/service-authorization/latest/reference/list_awsiamidentitycentersuccessortoawssinglesign-on.html * * 2025-02-24T21:48:13.281Z */ export declare enum AwsSsoActions { /** * Grants permission to connect a directory to be used by AWS IAM Identity Center * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ AssociateDirectory = "sso:AssociateDirectory", /** * Grants permission to create an association between a directory user or group an * d a profile * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ AssociateProfile = "sso:AssociateProfile", /** * Grants permission to attach a customer managed policy reference to a permission * set * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_AttachCustomerManagedPolicyReferenceToPermissionSet.html */ AttachCustomerManagedPolicyReferenceToPermissionSet = "sso:AttachCustomerManagedPolicyReferenceToPermissionSet", /** * Grants permission to attach an AWS managed policy to a permission set * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_AttachManagedPolicyToPermissionSet.html */ AttachManagedPolicyToPermissionSet = "sso:AttachManagedPolicyToPermissionSet", /** * Grants permission to assign access to a Principal for a specified AWS account u * sing a specified permission set * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_CreateAccountAssignment.html */ CreateAccountAssignment = "sso:CreateAccountAssignment", /** * Grants permission to create an application * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_CreateApplication.html */ CreateApplication = "sso:CreateApplication", /** * Grants permission to create an application assignment * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_CreateApplicationAssignment.html */ CreateApplicationAssignment = "sso:CreateApplicationAssignment", /** * Grants permission to add an application instance to AWS IAM Identity Center * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ CreateApplicationInstance = "sso:CreateApplicationInstance", /** * Grants permission to add a new certificate for an application instance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ CreateApplicationInstanceCertificate = "sso:CreateApplicationInstanceCertificate", /** * Grants permission to create an identity center instance * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_CreateInstance.html */ CreateInstance = "sso:CreateInstance", /** * Grants permission to enable the instance for ABAC and specify the attributes * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_CreateInstanceAccessControlAttributeConfiguration.html */ CreateInstanceAccessControlAttributeConfiguration = "sso:CreateInstanceAccessControlAttributeConfiguration", /** * Grants permission to add a managed application instance to AWS IAM Identity Cen * ter * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ CreateManagedApplicationInstance = "sso:CreateManagedApplicationInstance", /** * Grants permission to create a permission set * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_CreatePermissionSet.html */ CreatePermissionSet = "sso:CreatePermissionSet", /** * Grants permission to create a profile for an application instance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ CreateProfile = "sso:CreateProfile", /** * Grants permission to create a federation trust in a target account * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ CreateTrust = "sso:CreateTrust", /** * Grants permission to create a trusted token issuer for an instance * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_CreateTrustedTokenIssuer.html */ CreateTrustedTokenIssuer = "sso:CreateTrustedTokenIssuer", /** * Grants permission to delete a Principal's access from a specified AWS account u * sing a specified permission set * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeleteAccountAssignment.html */ DeleteAccountAssignment = "sso:DeleteAccountAssignment", /** * Grants permission to delete an application * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeleteApplication.html */ DeleteApplication = "sso:DeleteApplication", /** * Grants permission to delete an access scope to an application * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeleteApplicationAccessScope.html */ DeleteApplicationAccessScope = "sso:DeleteApplicationAccessScope", /** * Grants permission to delete an application assignment * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeleteApplicationAssignment.html */ DeleteApplicationAssignment = "sso:DeleteApplicationAssignment", /** * Grants permission to delete an authentication method to an application * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeleteApplicationAuthenticationMethod.html */ DeleteApplicationAuthenticationMethod = "sso:DeleteApplicationAuthenticationMethod", /** * Grants permission to delete a grant from an application * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeleteApplicationGrant.html */ DeleteApplicationGrant = "sso:DeleteApplicationGrant", /** * Grants permission to delete the application instance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ DeleteApplicationInstance = "sso:DeleteApplicationInstance", /** * Grants permission to delete an inactive or expired certificate from the applica * tion instance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ DeleteApplicationInstanceCertificate = "sso:DeleteApplicationInstanceCertificate", /** * Grants permission to delete the inline policy from a specified permission set * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeleteInlinePolicyFromPermissionSet.html */ DeleteInlinePolicyFromPermissionSet = "sso:DeleteInlinePolicyFromPermissionSet", /** * Grants permission to delete an identity center instance * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeleteInstance.html */ DeleteInstance = "sso:DeleteInstance", /** * Grants permission to disable ABAC and remove the attributes list for the instan * ce * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeleteInstanceAccessControlAttributeConfiguration.html */ DeleteInstanceAccessControlAttributeConfiguration = "sso:DeleteInstanceAccessControlAttributeConfiguration", /** * Grants permission to delete the managed application instance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ DeleteManagedApplicationInstance = "sso:DeleteManagedApplicationInstance", /** * Grants permission to delete a permission set * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeletePermissionSet.html */ DeletePermissionSet = "sso:DeletePermissionSet", /** * Grants permission to remove permissions boundary from a permission set * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeletePermissionsBoundaryFromPermissionSet.html */ DeletePermissionsBoundaryFromPermissionSet = "sso:DeletePermissionsBoundaryFromPermissionSet", /** * Grants permission to delete the permission policy associated with a permission * set * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ DeletePermissionsPolicy = "sso:DeletePermissionsPolicy", /** * Grants permission to delete the profile for an application instance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ DeleteProfile = "sso:DeleteProfile", /** * Grants permission to delete a trusted token issuer for an instance * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DeleteTrustedTokenIssuer.html */ DeleteTrustedTokenIssuer = "sso:DeleteTrustedTokenIssuer", /** * Grants permission to describe the status of the assignment creation request * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DescribeAccountAssignmentCreationStatus.html */ DescribeAccountAssignmentCreationStatus = "sso:DescribeAccountAssignmentCreationStatus", /** * Grants permission to describe the status of an assignment deletion request * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DescribeAccountAssignmentDeletionStatus.html */ DescribeAccountAssignmentDeletionStatus = "sso:DescribeAccountAssignmentDeletionStatus", /** * Grants permission to obtain information about an application * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DescribeApplication.html */ DescribeApplication = "sso:DescribeApplication", /** * Grants permission to retrieve an application assignment * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DescribeApplicationAssignment.html */ DescribeApplicationAssignment = "sso:DescribeApplicationAssignment", /** * Grants permission to describe an application provider * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DescribeApplicationProvider.html */ DescribeApplicationProvider = "sso:DescribeApplicationProvider", /** * Grants permission to obtain information about the directories for this account * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ DescribeDirectories = "sso:DescribeDirectories", /** * Grants permission to obtain information about an identity center instance * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DescribeInstance.html */ DescribeInstance = "sso:DescribeInstance", /** * Grants permission to get the list of attributes used by the instance for ABAC * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DescribeInstanceAccessControlAttributeConfiguration.html */ DescribeInstanceAccessControlAttributeConfiguration = "sso:DescribeInstanceAccessControlAttributeConfiguration", /** * Grants permission to describe a permission set * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DescribePermissionSet.html */ DescribePermissionSet = "sso:DescribePermissionSet", /** * Grants permission to describe the status for the given Permission Set Provision * ing request * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DescribePermissionSetProvisioningStatus.html */ DescribePermissionSetProvisioningStatus = "sso:DescribePermissionSetProvisioningStatus", /** * Grants permission to retrieve all the permissions policies associated with a pe * rmission set * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ DescribePermissionsPolicies = "sso:DescribePermissionsPolicies", /** * Grants permission to obtain the regions where your organization has enabled AWS * IAM Identity Center * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ DescribeRegisteredRegions = "sso:DescribeRegisteredRegions", /** * Grants permission to describe a trusted token issuer for an instance * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DescribeTrustedTokenIssuer.html */ DescribeTrustedTokenIssuer = "sso:DescribeTrustedTokenIssuer", /** * Grants permission to obtain information about the trust relationships for this * account * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ DescribeTrusts = "sso:DescribeTrusts", /** * Grants permission to detach a customer managed policy reference from a permissi * on set * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DetachCustomerManagedPolicyReferenceFromPermissionSet.html */ DetachCustomerManagedPolicyReferenceFromPermissionSet = "sso:DetachCustomerManagedPolicyReferenceFromPermissionSet", /** * Grants permission to detach the attached AWS managed policy from the specified * permission set * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_DetachManagedPolicyFromPermissionSet.html */ DetachManagedPolicyFromPermissionSet = "sso:DetachManagedPolicyFromPermissionSet", /** * Grants permission to disassociate a directory to be used by AWS IAM Identity Ce * nter * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ DisassociateDirectory = "sso:DisassociateDirectory", /** * Grants permission to disassociate a directory user or group from a profile * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ DisassociateProfile = "sso:DisassociateProfile", /** * Grants permission to get an access scope to an application * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_GetApplicationAccessScope.html */ GetApplicationAccessScope = "sso:GetApplicationAccessScope", /** * Grants permission to read assignment configurations for an application * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_GetApplicationAssignmentConfiguration.html */ GetApplicationAssignmentConfiguration = "sso:GetApplicationAssignmentConfiguration", /** * Grants permission to get an authentication method to an application * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_GetApplicationAuthenticationMethod.html */ GetApplicationAuthenticationMethod = "sso:GetApplicationAuthenticationMethod", /** * Grants permission to obtain details about a grant belonging to an application * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_GetApplicationGrant.html */ GetApplicationGrant = "sso:GetApplicationGrant", /** * Grants permission to retrieve details for an application instance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ GetApplicationInstance = "sso:GetApplicationInstance", /** * Grants permission to retrieve application template details * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ GetApplicationTemplate = "sso:GetApplicationTemplate", /** * Grants permission to obtain the inline policy assigned to the permission set * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_GetInlinePolicyForPermissionSet.html */ GetInlinePolicyForPermissionSet = "sso:GetInlinePolicyForPermissionSet", /** * Grants permission to retrieve details for an application instance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ GetManagedApplicationInstance = "sso:GetManagedApplicationInstance", /** * Grants permission to retrieve Mfa Device Management settings for the directory * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ GetMfaDeviceManagementForDirectory = "sso:GetMfaDeviceManagementForDirectory", /** * Grants permission to retrieve details of a permission set * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ GetPermissionSet = "sso:GetPermissionSet", /** * Grants permission to get permissions boundary for a permission set * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_GetPermissionsBoundaryForPermissionSet.html */ GetPermissionsBoundaryForPermissionSet = "sso:GetPermissionsBoundaryForPermissionSet", /** * Grants permission to retrieve all permission policies associated with a permiss * ion set * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ GetPermissionsPolicy = "sso:GetPermissionsPolicy", /** * Grants permission to retrieve a profile for an application instance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ GetProfile = "sso:GetProfile", /** * Grants permission to check if AWS IAM Identity Center is enabled * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ GetSSOStatus = "sso:GetSSOStatus", /** * Grants permission to retrieve shared configuration for the current SSO instance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ GetSharedSsoConfiguration = "sso:GetSharedSsoConfiguration", /** * Grants permission to retrieve configuration for the current SSO instance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ GetSsoConfiguration = "sso:GetSsoConfiguration", /** * Grants permission to retrieve the federation trust in a target account * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ GetTrust = "sso:GetTrust", /** * Grants permission to update the application instance by uploading an applicatio * n SAML metadata file provided by the service provider * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ ImportApplicationInstanceServiceProviderMetadata = "sso:ImportApplicationInstanceServiceProviderMetadata", /** * Grants permission to list the status of the AWS account assignment creation req * uests for a specified SSO instance * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListAccountAssignmentCreationStatus.html */ ListAccountAssignmentCreationStatus = "sso:ListAccountAssignmentCreationStatus", /** * Grants permission to list the status of the AWS account assignment deletion req * uests for a specified SSO instance * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListAccountAssignmentDeletionStatus.html */ ListAccountAssignmentDeletionStatus = "sso:ListAccountAssignmentDeletionStatus", /** * Grants permission to list the assignee of the specified AWS account with the sp * ecified permission set * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListAccountAssignments.html */ ListAccountAssignments = "sso:ListAccountAssignments", /** * Grants permission to list accounts assigned to user or group * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListAccountAssignmentsForPrincipal.html */ ListAccountAssignmentsForPrincipal = "sso:ListAccountAssignmentsForPrincipal", /** * Grants permission to list all the AWS accounts where the specified permission s * et is provisioned * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListAccountsForProvisionedPermissionSet.html */ ListAccountsForProvisionedPermissionSet = "sso:ListAccountsForProvisionedPermissionSet", /** * Grants permission to list access scopes to an application * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListApplicationAccessScopes.html */ ListApplicationAccessScopes = "sso:ListApplicationAccessScopes", /** * Grants permission to list application assignments * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListApplicationAssignments.html */ ListApplicationAssignments = "sso:ListApplicationAssignments", /** * Grants permission to list applications assigned to user or group * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListApplicationAssignmentsForPrincipal.html */ ListApplicationAssignmentsForPrincipal = "sso:ListApplicationAssignmentsForPrincipal", /** * Grants permission to list authentication methods to an application * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListApplicationAuthenticationMethods.html */ ListApplicationAuthenticationMethods = "sso:ListApplicationAuthenticationMethods", /** * Grants permission to list grants from an application * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListApplicationGrants.html */ ListApplicationGrants = "sso:ListApplicationGrants", /** * Grants permission to retrieve all of the certificates for a given application i * nstance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ ListApplicationInstanceCertificates = "sso:ListApplicationInstanceCertificates", /** * Grants permission to retrieve all application instances * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ ListApplicationInstances = "sso:ListApplicationInstances", /** * Grants permission to list application providers * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListApplicationProviders.html */ ListApplicationProviders = "sso:ListApplicationProviders", /** * Grants permission to retrieve all supported application templates * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ ListApplicationTemplates = "sso:ListApplicationTemplates", /** * Grants permission to retrieve all applications associated with the instance of * IAM Identity Center * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListApplications.html */ ListApplications = "sso:ListApplications", /** * Grants permission to list the customer managed policy references that are attac * hed to a permission set * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListCustomerManagedPolicyReferencesInPermissionSet.html */ ListCustomerManagedPolicyReferencesInPermissionSet = "sso:ListCustomerManagedPolicyReferencesInPermissionSet", /** * Grants permission to retrieve details about the directory connected to AWS IAM * Identity Center * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ ListDirectoryAssociations = "sso:ListDirectoryAssociations", /** * Grants permission to list the SSO Instances that the caller has access to * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListInstances.html */ ListInstances = "sso:ListInstances", /** * Grants permission to list the AWS managed policies that are attached to a speci * fied permission set * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListManagedPoliciesInPermissionSet.html */ ListManagedPoliciesInPermissionSet = "sso:ListManagedPoliciesInPermissionSet", /** * Grants permission to list the status of the Permission Set Provisioning request * s for a specified SSO instance * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListPermissionSetProvisioningStatus.html */ ListPermissionSetProvisioningStatus = "sso:ListPermissionSetProvisioningStatus", /** * Grants permission to retrieve all permission sets * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListPermissionSets.html */ ListPermissionSets = "sso:ListPermissionSets", /** * Grants permission to list all the permission sets that are provisioned to a spe * cified AWS account * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListPermissionSetsProvisionedToAccount.html */ ListPermissionSetsProvisionedToAccount = "sso:ListPermissionSetsProvisionedToAccount", /** * Grants permission to retrieve the directory user or group associated with the p * rofile * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ ListProfileAssociations = "sso:ListProfileAssociations", /** * Grants permission to retrieve all profiles for an application instance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ ListProfiles = "sso:ListProfiles", /** * Grants permission to list the tags that are attached to a specified resource * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListTagsForResource.html */ ListTagsForResource = "sso:ListTagsForResource", /** * Grants permission to list trusted token issuers for an instance * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ListTrustedTokenIssuers.html */ ListTrustedTokenIssuers = "sso:ListTrustedTokenIssuers", /** * Grants permission to provision a specified permission set to the specified targ * et * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_ProvisionPermissionSet.html */ ProvisionPermissionSet = "sso:ProvisionPermissionSet", /** * Grants permission to create/update an access scope to an application * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_PutApplicationAccessScope.html */ PutApplicationAccessScope = "sso:PutApplicationAccessScope", /** * Grants permission to add assignment configurations to an application * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_PutApplicationAssignmentConfiguration.html */ PutApplicationAssignmentConfiguration = "sso:PutApplicationAssignmentConfiguration", /** * Grants permission to create/update an authentication method to an application * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_PutApplicationAuthenticationMethod.html */ PutApplicationAuthenticationMethod = "sso:PutApplicationAuthenticationMethod", /** * Grants permission to create/update a grant to an application * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_PutApplicationGrant.html */ PutApplicationGrant = "sso:PutApplicationGrant", /** * Grants permission to attach an IAM inline policy to a permission set * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_PutInlinePolicyToPermissionSet.html */ PutInlinePolicyToPermissionSet = "sso:PutInlinePolicyToPermissionSet", /** * Grants permission to put Mfa Device Management settings for the directory * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ PutMfaDeviceManagementForDirectory = "sso:PutMfaDeviceManagementForDirectory", /** * Grants permission to add permissions boundary to a permission set * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_PutPermissionsBoundaryToPermissionSet.html */ PutPermissionsBoundaryToPermissionSet = "sso:PutPermissionsBoundaryToPermissionSet", /** * Grants permission to add a policy to a permission set * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ PutPermissionsPolicy = "sso:PutPermissionsPolicy", /** * Grants permission to search for groups within the associated directory * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ SearchGroups = "sso:SearchGroups", /** * Grants permission to search for users within the associated directory * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ SearchUsers = "sso:SearchUsers", /** * Grants permission to initialize AWS IAM Identity Center * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ StartSSO = "sso:StartSSO", /** * Grants permission to associate a set of tags with a specified resource * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_TagResource.html */ TagResource = "sso:TagResource", /** * Grants permission to disassociate a set of tags from a specified resource * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_UntagResource.html */ UntagResource = "sso:UntagResource", /** * Grants permission to update an application * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_UpdateApplication.html */ UpdateApplication = "sso:UpdateApplication", /** * Grants permission to set a certificate as the active one for this application i * nstance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ UpdateApplicationInstanceActiveCertificate = "sso:UpdateApplicationInstanceActiveCertificate", /** * Grants permission to update display data of an application instance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ UpdateApplicationInstanceDisplayData = "sso:UpdateApplicationInstanceDisplayData", /** * Grants permission to update federation response configuration for the applicati * on instance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ UpdateApplicationInstanceResponseConfiguration = "sso:UpdateApplicationInstanceResponseConfiguration", /** * Grants permission to update federation response schema configuration for the ap * plication instance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ UpdateApplicationInstanceResponseSchemaConfiguration = "sso:UpdateApplicationInstanceResponseSchemaConfiguration", /** * Grants permission to update security details for the application instance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ UpdateApplicationInstanceSecurityConfiguration = "sso:UpdateApplicationInstanceSecurityConfiguration", /** * Grants permission to update service provider related configuration for the appl * ication instance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ UpdateApplicationInstanceServiceProviderConfiguration = "sso:UpdateApplicationInstanceServiceProviderConfiguration", /** * Grants permission to update the status of an application instance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ UpdateApplicationInstanceStatus = "sso:UpdateApplicationInstanceStatus", /** * Grants permission to update the user attribute mappings for your connected dire * ctory * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ UpdateDirectoryAssociation = "sso:UpdateDirectoryAssociation", /** * Grants permission to update an identity center instance * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_UpdateInstance.html */ UpdateInstance = "sso:UpdateInstance", /** * Grants permission to update the attributes to use with the instance for ABAC * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_UpdateInstanceAccessControlAttributeConfiguration.html */ UpdateInstanceAccessControlAttributeConfiguration = "sso:UpdateInstanceAccessControlAttributeConfiguration", /** * Grants permission to update the status of a managed application instance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ UpdateManagedApplicationInstanceStatus = "sso:UpdateManagedApplicationInstanceStatus", /** * Grants permission to update the permission set * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_UpdatePermissionSet.html */ UpdatePermissionSet = "sso:UpdatePermissionSet", /** * Grants permission to update the profile for an application instance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ UpdateProfile = "sso:UpdateProfile", /** * Grants permission to update the configuration for the current SSO instance * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ UpdateSSOConfiguration = "sso:UpdateSSOConfiguration", /** * Grants permission to update the federation trust in a target account * * See https://docs.aws.amazon.com/singlesignon/latest/userguide/iam-auth-access-using-id-policies.html#policyexample */ UpdateTrust = "sso:UpdateTrust", /** * Grants permission to update a trusted token issuer for an instance * * See https://docs.aws.amazon.com/singlesignon/latest/APIReference/API_UpdateTrustedTokenIssuer.html */ UpdateTrustedTokenIssuer = "sso:UpdateTrustedTokenIssuer" }