IAM makes it easier for you to manage permissions for AWS services accessing your resources

This condition key is similar to aws:CalledVia and aws:CalledViaFirst, but instead of being limited to a specific AWS service (i.e. Athena), it can be used to allow or deny access to any AWS service (hence it’s either set to true or false) that makes a request on behalf of the IAM principal to access your resources as discussed in data access pattern #2.

Read full article on AWS Security Blog


