{ "Version": "2012-10-17", "Statement": { "Sid": "AllowList", "Effect": "Deny", "Resource": "*", "NotAction": ["access-analyzer:*", "account:*", "acm:*", "acm-pca:*", "amplify:*", "amplifybackend:*", "apigateway:*", "application-autoscaling:*", "appmesh:*", "appstream:*", "appsync:*", "artifact:*", "athena:*", "auditmanager:*", "autoscaling:*", "autoscaling-plans:*", "aws-portal:*", "backup:*", "backup-storage:*", "batch:*", "cassandra:*", "chatbot:*", "chime:*", "clouddirectory:*", "cloudformation:*", "cloudfront:*", "cloudhsm:*", "cloudtrail:*", "cloudwatch:*", "codebuild:*", "codecommit:*", "codedeploy:*", "codepipeline:*", "codestar:*", "codestar-connections:*", "codestar-notifications:*", "cognito-identity:*", "cognito-idp:*", "cognito-sync:*", "comprehend:*", "comprehendmedical:*", "config:*", "connect:*", "controltower:*", "databrew:*", "dataexchange:*", "datasync:*", "detective:*", "devicefarm:*", "directconnect:*", "dms:*", "ds:*", "dynamodb:*", "ebs:*", "ec2:*", "ec2messages:*", "ecr:*", "ecs:*", "eks:*", "elasticache:*", "elasticbeanstalk:*", "elasticfilesystem:*", "elasticloadbalancing:*", "elasticmapreduce:*", "es:*", "events:*", "execute-api:*", "firehose:*", "fms:*", "forecast:*", "freertos:*", "fsx:*", "glacier:*", "globalaccelerator:*", "glue:*", "greengrass:*", "groundstation:*", "guardduty:*", "health:*", "iam:*", "importexport:*", "inspector:*", "iot:*", "iot-device-tester:*", "iot1click:*", "iotanalytics:*", "iotdeviceadvisor:*", "iotevents:*", "iotwireless:*", "kafka:*", "kendra:*", "kinesis:*", "kinesisanalytics:*", "kinesisvideo:*", "kms:*", "lakeformation:*", "lambda:*", "license-manager:*", "logs:*", "macie:*", "macie2:*", "mediaconnect:*", "mediaconvert:*", "medialive:*", "mobiletargeting:*", "mq:*", "neptune-db:*", "opsworks:*", "opsworks-cm:*", "organizations:*", "outposts:*", "personalize:*", "polly:*", "qldb:*", "quicksight:*", "rds:*", "rds-data:*", "rds-db:*", "redshift:*", "rekognition:*", "resource-groups:*", "robomaker:*", "route53:*", "route53domains:*", "route53resolver:*", "s3:*", "sagemaker:*", "sdb:*", "secretsmanager:*", "securityhub:*", "serverlessrepo:*", "servicecatalog:*", "servicediscovery:*", "ses:*", "shield:*", "sms:*", "sms-voice:*", "snowball:*", "sns:*", "sqs:*", "ssm:*", "ssmmessages:*", "sso:*", "sso-directory:*", "states:*", "storagegateway:*", "sts:*", "support:*", "swf:*", "tag:*", "textract:*", "timestream:*", "transcribe:*", "transfer:*", "translate:*", "trustedadvisor:*", "waf:*", "waf-regional:*", "wafv2:*", "workdocs:*", "worklink:*", "workmail:*", "workspaces:*", "xray:*"] } }