[ "organizations:*", "account:*", "controltower:*", "sso:*" ], "Resource": "*" }, { "Effect": "Allow", "Action": [ "account:GetAccountInformation", "account:GetPrimaryEmail", "account:ListRegions", "organizations:DescribeOrganization", "iam:*" ], "Resource": "*" }, { "Effect": "Deny", "Action": "iam:CreatePolicyVersion", "Resource": "arn:aws:iam::${AccountId}:policy/CustomPowerUserAccess" } ] }