Skip to main content
Your Cloud Capital contact has sent you this page as part of your onboarding. Complete this check before they send your AWS Billing Transfer invite. If you find and fix any issues now, your billing transfer will go through smoothly — if issues are found only after the invite is accepted, you’ll need to fix them before data can flow and re-attempt the transfer.
Most accounts are unaffected. If your AWS account or organization was created on or after March 6, 2023, you can skip straight to verifying you’re not affected — the tool will confirm this in seconds.

Why this check exists

AWS retired a set of legacy IAM actions (aws-portal:*) used to control access to Billing and Cost Management. If your AWS account was created before March 6, 2023, some of your IAM policies may still reference these old actions — and AWS Billing Transfer requires the newer fine-grained permissions to work correctly. The good news: AWS provides a free tool that scans your policies and tells you exactly what (if anything) needs to change, with suggested fixes ready to copy.

Check your affected policies

1

Sign in to your AWS management (payer) account

For the tool to show issues across your entire AWS Organization, sign in as a role or user with Organizational level access in your management (payer) account — organization admin or root access to that account works best so you can see all possible issues across the organization instead of just going account by account.If you only have access to a single member account, the tool will still show issues for that account.
2

Open the Affected Policies tool

Go directly to the tool:https://console.aws.amazon.com/poliden/home?region=us-east-1#/This is AWS’s built-in IAM policy migration tool under Billing preferences. You may be prompted to sign in if you’re not already.
3

Review the results

The tool will either show:✅ No policies listed — You’re all set. No action is required. Let your Cloud Capital contact know you’re clear to receive the billing transfer invite.⚠️ One or more policies listed — Each entry shows the policy name, the deprecated actions it contains, and a suggested updated policy you can copy directly. Follow the migration steps below to resolve them, then return here to confirm the list is empty.
The tool scans IAM identity-based policies only — not Service Control Policies (SCPs). If your organization uses SCPs to restrict billing access, review those separately. See the FAQ below for details.

Fixing affected policies

If the Affected Policies tool listed one or more policies, follow the steps below to update them. Come back to the tool afterward to confirm the list is empty, then let your Cloud Capital contact know you’re ready.

Frequently asked questions

No — accounts created on or after that date already enforce fine-grained actions by default. The Affected Policies tool will show an empty list, confirming you’re ready to proceed. Just let your Cloud Capital contact know.
No — as long as you retain the old aws-portal:* actions in your policy during the transition, access remains uninterrupted. The migration adds new fine-grained actions alongside the existing ones; it does not remove the old ones.
No — use the Bulk Policy Migrator in your management (payer) account. It scans all member accounts at once and lets you apply recommended migrations in Customize mode. See the Bulk Policy Migrator tab above for step-by-step instructions.
The Affected Policies tool only scans IAM identity-based policies. SCPs are not included. If your organization uses SCPs to restrict billing or cost management access, review those separately using the AWS action mapping reference.
You may encounter permission errors when accepting the invite, or cost and billing data may not flow through correctly after onboarding. Completing this check first ensures the transfer goes through without interruption.

All clear? Let your Cloud Capital contact know

Once the Affected Policies tool shows an empty list, you’re ready for the billing transfer invite. Reach out to your Cloud Capital contact and they’ll send it right away.

AWS Affected Policies Tool

Open the tool directly to check your IAM policies.

AWS fine-grained permissions reference

Official AWS documentation on the Affected Policies Tool.