AWS CLI IAM and STS Cheat Sheet/Detach a managed policy from a role

Remove a managed policy from a role.

Section: IAM Policies

Detach a managed policy from a role

bash
bash
aws iam detach-role-policy --role-name AppRole --policy-arn arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess
Explanation

Used during least-privilege cleanup.

Learn the surrounding workflow

Compare similar commands or jump into common fixes when this command is part of a bigger troubleshooting path.

Related commands

Same sheet · prioritizing IAM Policies
Attach a managed policy to a role
Grant a role the permissions from a managed policy.
OpenIn sheetbashsame section
List managed policies
Show AWS-managed and customer-managed policies.
OpenIn sheetbashsame section
Get policy metadata
Read high-level metadata for a managed policy.
OpenIn sheetbashsame section
Get policy document version
Read the JSON document for a specific policy version.
OpenIn sheetbashsame section
Create a managed policy
Create a new customer-managed policy from JSON.
OpenIn sheetbashsame section
Simulate effective permissions
Test whether a principal can perform an action on a resource.
OpenIn sheetbashsame section