79766196

Date: 2025-09-16 11:55:01
Score: 0.5
Natty:
Report link

TLDR: you can't use wildcards in Principals in IAM Policy Statements....

From what I understand, when you put in a principal in a IAM statement - behind the scenes, it translates that to the internal ID of the user/role. This is to prevent someone maliciously naming something similar to get access - we can argue if someone can create IAM users/roles, then you already have a pretty major issue.... This behavior is why you can't use wildcards in IAM Principals.

Reasons:
  • No code block (0.5):
Posted by: Dan G