Why this check exists
AWS retired a set of legacy IAM actions (aws-portal:*) used to control access to Billing and Cost Management. If your AWS account was created before March 6, 2023, some of your IAM policies may still reference these old actions — and AWS Billing Transfer requires the newer fine-grained permissions to work correctly.
The good news: AWS provides a free tool that scans your policies and tells you exactly what (if anything) needs to change, with suggested fixes ready to copy.
Check your affected policies
Sign in to your AWS management (payer) account
Open the Affected Policies tool
Review the results
Fixing affected policies
If the Affected Policies tool listed one or more policies, follow the steps below to update them. Come back to the tool afterward to confirm the list is empty, then let your Cloud Capital contact know you’re ready.- Using the Affected Policies Tool (recommended)
- Bulk Policy Migrator (AWS Organizations)
- Updating policies in code (IaC)
Copy the updated policy
AffectedPoliciesMigrator) with the equivalent fine-grained actions.Open the policy in IAM
Edit and paste the updated policy
Repeat for all affected policies
Verify the migration is complete
Frequently asked questions
My account was created after March 6, 2023. Do I need to do anything?
My account was created after March 6, 2023. Do I need to do anything?
Will my team lose access during the migration?
Will my team lose access during the migration?
aws-portal:* actions in your policy during the transition, access remains uninterrupted. The migration adds new fine-grained actions alongside the existing ones; it does not remove the old ones.I manage multiple AWS accounts. Do I need to do this for each one?
I manage multiple AWS accounts. Do I need to do this for each one?
Does this affect Service Control Policies (SCPs)?
Does this affect Service Control Policies (SCPs)?
What happens if I don't complete this before the billing transfer invite?
What happens if I don't complete this before the billing transfer invite?

