Using the console to bulk migrate your policies
Note
The following AWS Identity and Access Management (IAM) actions have reached the end of standard support on July 2023:
-
aws-portal
namespace -
purchase-orders:ViewPurchaseOrders
-
purchase-orders:ModifyPurchaseOrders
If you're using AWS Organizations, you can use the bulk policy migrator scripts or bulk policy migrator to update polices from your payer account. You can also use the old to granular action mapping reference to verify the IAM actions that need to be added.
If you have an AWS account, or are a part of an AWS Organizations created on or after March 6, 2023, 11:00 AM (PDT), the fine-grained actions are already in effect in your organization.
This section covers how you can use the AWS Billing and Cost Management console
- Using the AWS recommended migration process
-
This is a streamlined, single-action process where you migrates legacy actions to the fine-grained actions as mapped by AWS. For more information, see Using recommended actions to bulk migrate legacy policies.
- Using the customized migration process
-
This process allows you to review and change the actions recommended by AWS prior to the bulk migration, as well as customize which accounts in your organization are migrated. For more information, see Customizing actions to bulk migrate legacy policies.
Prerequisites for bulk migrating using the console
Both migration options require you to consent in the console so that AWS can recommend fine-grained actions to the legacy IAM actions you have assigned. To do this, you will need to login to your AWS account as an IAM principal with the following IAM actions to continue with the policy updates.
Topics
Confirming your migration
You can see if there are any AWS Organizations accounts that still need to migrate by using the migration tool.
To confirm if all accounts migrated
Sign in to the AWS Management Console
. In the search bar at the top of the page, enter
Bulk Policy Migrator
.On the Manage new IAM actions page, choose the Migrate accounts tab.
All accounts have migrated successfully if the table doesn't show any remaining accounts.