0PricingLogin
AWS Security Academy · Lesson

Delegating Role Creation Safely

Let teams build roles without exceeding a set guardrail.

The Delegation Dilemma

Teams move faster when they can create their own IAM roles and policies, but unrestricted IAM access is dangerous: a developer could grant themselves administrator rights. The challenge is letting teams build roles while guaranteeing those roles stay within safe limits. Permission boundaries make this possible, a frequently tested exam scenario.

The Privilege-Escalation Risk

Without guardrails, giving someone iam:CreateRole and iam:AttachRolePolicy is effectively giving them admin. They could create a role with AdministratorAccess and assume it. This privilege-escalation path is exactly what safe delegation must close while still allowing legitimate role creation.

All lessons in this course

  1. What a Permission Boundary Limits
  2. Delegating Role Creation Safely
  3. Organizations, OUs, and SCP Strategy
  4. How SCPs Combine with IAM Permissions
← Back to AWS Security Academy