Build IAM Identity Center permission set configurations with managed policies, inline policies, and session settings.
Build IAM Identity Center (SSO) permission set configurations with managed policies, inline policies, and session settings.
Required Fields
NameInstanceArnSessionDurationOutput will appear here...Build an IAM Identity Center (successor to AWS SSO) permission set combining AWS managed policies, an inline policy, customer-managed policy references, and a session duration (ISO 8601 duration format, PT8H meaning 8 hours), which becomes an IAM role provisioned into each assigned account when the permission set is applied. A permission set change doesn't take effect in already-provisioned accounts until you explicitly re-provision it, editing PowerUserAccess's inline policy and saving doesn't retroactively update the IAM role already sitting in 40 assigned accounts, that's a separate, explicit reprovision step.
Permission set changes require an explicit re-provision step to actually reach already-assigned accounts, build that into your change process (a documented step or automation), not just 'edit and save' as if it were a live policy update.
CustomerManagedPolicyReferences requires the referenced policy to pre-exist by exact name and path in every target account, this is the most common cause of a permission set provisioning failure that isn't obvious from the permission set definition alone.
An inline Deny statement layered over a broad managed policy (as in the DenyIAMChanges example) is evaluated with explicit-deny-wins semantics, so it reliably carves out the exception even against a very permissive base policy, a pattern worth using deliberately rather than trying to construct an equivalent Allow-only policy from scratch.
The builder validates that Name, InstanceArn, and SessionDuration resolve before accepting the JSON as a valid CreatePermissionSet request, the fields IAM Identity Center needs to create the permission set itself; the managed/inline/customer-managed policy attachments and permissions boundary are separate API calls layered on top in practice, and the builder can't verify a referenced customer-managed policy actually exists in your target accounts.
Was this tool helpful?
Disclaimer: This tool runs entirely in your browser. No data is sent to our servers. Always verify outputs before using them in production. AWS, Azure, and GCP are trademarks of their respective owners.