- Más nuevo
- Más votos
- Más comentarios
Based on the information you've provided, it appears that your AWS account (256883135516) is experiencing a service-level restriction that's preventing even the root user from creating AWS Glue Crawlers and Jobs, despite having all the necessary IAM permissions and configurations in place.
The error message "Account 256883135516 is denied access" combined with the fact that the operation is being blocked before IAM evaluation (as indicated by the null responseElements in CloudTrail) strongly suggests this is an account-level restriction rather than a permissions issue.
Since you've already verified that:
- No Service Control Policies (SCPs) are applied to the account
- The root user has MFA enabled and proper authentication
- The IAM roles have the correct trust policies and permissions
- The account is active with billing in good standing
- Service quotas are not exceeded
- The issue persists across multiple regions
This appears to be a problem that requires AWS Support intervention. When an account-level restriction is preventing access to a service, even for the root user, it typically indicates one of the following:
- There might be an internal AWS restriction on the account for the Glue service
- There could be an issue related to how the account was set up within your organization
- There might be a service-specific limitation that was applied to your account
The recommended course of action is to open a case with AWS Support under the "Account and billing" category. This type of inquiry can be made free of charge, even without a support plan. AWS Support will be able to investigate any account-level restrictions that might be preventing you from using Glue services and provide a resolution.
When opening the case, include all the information you've provided here, especially the CloudTrail event details and the troubleshooting steps you've already taken, as this will help expedite the resolution process.
Sources
Root User Is Denied Access While Creating Glue Crawler and IAM Glue ETL | AWS re:Post
Unable to save in gluestudio: | AWS re:Post
Criar um crawler | AWS re:Post
AWS Glue Crawler | AWS re:Post
Contenido relevante
- preguntada hace 2 meses
- preguntada hace 17 días
- preguntada hace 10 meses
- preguntada hace 5 meses
- OFICIAL DE AWSActualizada hace 7 meses
- OFICIAL DE AWSActualizada hace 4 años
