I've searched quite a bit but cannot find a policy to allow a user to create IAM Roles from both the management console (AWS website) and from AWS CLI.

1 Answer

You can check out this link to get the list of the IAM permissions

From the available and acceptable IAM permissions, you can add as much as you can


    "Version": "2012-10-17",

    "Statement": [


            "Action": [







            "Effect": "Allow",

            "Resource": "*"




