A permission boundary is an advanced IAM feature that sets the maximum permissions an IAM user or role can have — even if their attached policies grant more. It’s a ceiling, not a grant.
Boundaries vs SCPs vs policies
An identity’s effective permissions are the intersection of its policies AND its permission boundary. Boundaries apply to individual IAM users/roles (often used so teams can create roles safely without exceeding limits). SCPs (AWS Organizations) do the same at the whole-account level. Policies grant; boundaries cap.
Test yourself
You let developers create their own IAM roles but must guarantee those roles can never exceed a defined set of permissions. What enforces this ceiling?
- A stronger IAM policy
- An IAM permission boundary
- A security group
- A resource-based policy
👉 Click to reveal the answer & explanation
Correct answer: B. A permission boundary caps the maximum permissions an IAM user/role can have, regardless of attached policies — ideal for safe delegation. A stronger policy (A) grants, not caps; security groups (C) filter network traffic; resource-based policies (D) attach to resources, not identities as a ceiling.
Related topics
AWS IAM · IAM roles vs policies · AWS Organizations
Ready to pass the AWS Solutions Architect Associate (SAA-C03)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the SAA-C03 Practice Exams →or try 25 free questions first