A permission boundary is an advanced IAM feature that sets the maximum permissions an IAM user or role can have — even if their attached policies grant more. It’s a ceiling, not a grant.

Boundaries vs SCPs vs policies

An identity’s effective permissions are the intersection of its policies AND its permission boundary. Boundaries apply to individual IAM users/roles (often used so teams can create roles safely without exceeding limits). SCPs (AWS Organizations) do the same at the whole-account level. Policies grant; boundaries cap.

Test yourself

Practice question

You let developers create their own IAM roles but must guarantee those roles can never exceed a defined set of permissions. What enforces this ceiling?

  1. A stronger IAM policy
  2. An IAM permission boundary
  3. A security group
  4. A resource-based policy
👉 Click to reveal the answer & explanation

Correct answer: B. A permission boundary caps the maximum permissions an IAM user/role can have, regardless of attached policies — ideal for safe delegation. A stronger policy (A) grants, not caps; security groups (C) filter network traffic; resource-based policies (D) attach to resources, not identities as a ceiling.

Related topics

AWS IAM · IAM roles vs policies · AWS Organizations

CloudExamPro Premium

Ready to pass the AWS Solutions Architect Associate (SAA-C03)?

Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.

  • ✓  6 full-length practice exams
  • ✓  A detailed explanation for every single question
  • ✓  Realistic, scenario-based questions — not memory dumps
  • ✓  Lifetime access, kept current for 2026

Get the SAA-C03 Practice Exams →or try 25 free questions first

Limited-time offer · ends in --Days:--Hrs:--Min:--Sec
Get Instant Access