AWS IAM now supports 20 managed policies per role by default
Posted on: Aug 19, 2026
AWS Identity and Access Management (IAM) has increased the default quota for managed policies per role from 10 to 20.
This higher default quota reduces the need to make Service Quota requests when following IAM best practices like separating permissions into purpose-specific policies or when onboarding to AWS Partner products that require attaching additional managed policies. If you need more than 20 managed policies per role, you can request a quota increase up to 25 using Service Quotas.
This change is available in all commercial AWS Regions, AWS GovCloud (US) and China Regions and applies automatically to all IAM roles in your account with no action required. To learn more, see IAM and AWS STS quotas in the IAM User Guide.