本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。
AWSFMAdminReadOnlyAccess
描述: AWS FM 管理员的只读访问权限,允许监控 AWS FM 操作
AWSFMAdminReadOnlyAccess
是一项 AWS 托管式策略。
使用此策略
您可以将 AWSFMAdminReadOnlyAccess
附加到您的用户、组和角色。
策略详细信息
-
类型: AWS 托管策略
-
创建时间:2018 年 5 月 9 日 20:07 UTC
-
编辑时间:2022 年 10 月 31 日 22:42 UTC
-
ARN:
arn:aws:iam::aws:policy/AWSFMAdminReadOnlyAccess
策略版本
策略版本:v2 (默认值)
此策略的默认版本是定义策略权限的版本。当使用该策略的用户或角色请求访问 AWS 资源时, AWS 会检查策略的默认版本以确定是否允许该请求。
JSON 策略文档
{
"Version" : "2012-10-17",
"Statement" : [
{
"Effect" : "Allow",
"Action" : [
"fms:Get*",
"fms:List*",
"waf:Get*",
"waf:List*",
"waf-regional:Get*",
"waf-regional:List*",
"firehose:ListDeliveryStreams",
"organizations:DescribeOrganization",
"organizations:DescribeAccount",
"organizations:ListRoots",
"organizations:ListChildren",
"organizations:ListAccounts",
"organizations:ListAccountsForParent",
"organizations:ListOrganizationalUnitsForParent",
"shield:GetSubscriptionState",
"route53resolver:ListFirewallRuleGroups",
"route53resolver:GetFirewallRuleGroup",
"wafv2:ListRuleGroups",
"wafv2:ListAvailableManagedRuleGroups",
"wafv2:CheckCapacity",
"wafv2:ListAvailableManagedRuleGroupVersions",
"network-firewall:DescribeRuleGroup",
"network-firewall:DescribeRuleGroupMetadata",
"network-firewall:ListRuleGroups",
"ec2:DescribeAvailabilityZones",
"ec2:DescribeRegions"
],
"Resource" : "*"
},
{
"Effect" : "Allow",
"Action" : [
"s3:GetBucketPolicy"
],
"Resource" : [
"arn:aws:s3:::aws-waf-logs-*"
]
},
{
"Effect" : "Allow",
"Action" : [
"organizations:ListDelegatedAdministrators"
],
"Resource" : "*",
"Condition" : {
"StringEquals" : {
"organizations:ServicePrincipal" : [
"fms.amazonaws.com"
]
}
}
}
]
}