IAM Policy Simulator moves to the IAM console and adds additional capabilities
AWS IAM Policy Simulator has moved into the IAM console and now supports testing service control policies, with new scenario modeling and cross-account reporting features.
The useful question is what changes for users, developers or buyers, and whether the announcement stays industry context or becomes something people can actually use.
AWS Identity and Access Management (IAM) has integrated the IAM Policy Simulator directly into the IAM console, replacing the standalone simulator site. This change allows users to test and validate IAM policies within the same interface where they manage identities and policies, streamlining workflows for security and platform teams.
The update introduces the ability to test service control policies (SCPs), enabling organizations to evaluate how SCPs interact with identity and resource policies across their hierarchy. Users can now simulate condition keys such as Region restrictions and tag requirements via the API, providing more granular control over policy validation.
New flexibility in the simulator allows teams to exclude specific policies for "what if" scenario testing, helping to assess the impact of policy removals. Cross-account simulations now report decisions per policy, with denied requests showing only the policies that contributed to the outcome, improving transparency in access decisions.
These enhancements support automated policy unit testing, detection of over-permissive access, and validation of organizational guardrails. The updated IAM Policy Simulator is available in all AWS Regions where the service is currently supported and can be accessed directly from the IAM console navigation pane.