IAM Policy Simulator moves to the IAM console and adds additional capabilities
The IAM Policy Simulator is now integrated into the IAM console, adding support for testing SCPs, condition key effects, and policy exclusions
The IAM Policy Simulator has been integrated into the IAM console, replacing the standalone simulator site. This allows you to test policies in the same place where you manage your identities and policies. You can now include service control policies (SCPs) in your simulation to test how your organization's SCP hierarchy interacts with identity and resource policies. Through the API, you can test how condition keys such as region restrictions and tag requirements affect the outcome. New flexibility allows you to exclude specific policies to model "what if I remove this policy?" scenarios. Cross-account simulations now report per-policy decisions for identity and resource-based policies, with the matched statements returned for a denied request reflecting only the policies that drove the decision. These changes help teams automate policy unit testing, detect over-permissive access, and validate guardrails with greater confidence. These features are available in all AWS Regions where the IAM Policy Simulator is available. Access the IAM Policy Simulator in the IAM console by selecting Policy simulator in the navigation pane.