OFICIAL AWS What's New

IAM Policy Simulator moves to the IAM console and adds additional capabilities

What happened
Based on AWS What's New · Jul 30, 2026

AWS IAM Policy Simulator has moved into the IAM console and now supports testing service control policies, with new scenario modeling and cross-account reporting features.

Key points
·
AWS Identity and Access Management (IAM) announces a major update to IAM Policy Simulator, the tool you use to test and validate the permissions your IAM policies grant before you deploy them.
·
This update changes the simulator in three ways: it now lives in the IAM console, it can test service control policies (SCPs), and it adds flexibility to model more of the scenarios that security and platform teams simulate in practice.
·
IAM Policy Simulator is now part of the IAM console, replacing the standalone simulator site, so you can test policies in the same place you manage your identities and policies.
·
You can also now include SCPs in your simulation to test how your organization's SCP hierarchy interacts with identity and resource policies, and through the API, test how condition keys such as Region restrictions and tag requirements affect the outcome.

AWS Identity and Access Management (IAM) has integrated the IAM Policy Simulator directly into the IAM console, replacing the standalone simulator site. This change allows users to test and validate IAM policies within the same interface where they manage identities and policies, streamlining workflows for security and platform teams.

The update introduces the ability to test service control policies (SCPs), enabling organizations to evaluate how SCPs interact with identity and resource policies across their hierarchy. Users can now simulate condition keys such as Region restrictions and tag requirements via the API, providing more granular control over policy validation.

New flexibility in the simulator allows teams to exclude specific policies for "what if" scenario testing, helping to assess the impact of policy removals. Cross-account simulations now report decisions per policy, with denied requests showing only the policies that contributed to the outcome, improving transparency in access decisions.

These enhancements support automated policy unit testing, detection of over-permissive access, and validation of organizational guardrails. The updated IAM Policy Simulator is available in all AWS Regions where the service is currently supported and can be accessed directly from the IAM console navigation pane.

Original source → Deals on Clipraptor.com →