æš©éãšã©ãŒãåé€ããŠãã£ã«ã¿ãªã³ã°ãã { "Sid":"Deny unintended access to KMS key", "Effect":"Deny", "Principal":"*", "Action":[ "kms:DescribeKey", "kms:GetKeyPolicy", "kms:List*" ], "Resource":"*", "Condition":{ "ArnNotLikeIfExists":{ "aws:PrincipalArn":[ "arn:aws:iam::<ACCOUNT_ID>:role/aws-service-role/access-analyzer.amazonaws.com/AWSServiceRoleForAccessAnalyzer", "arn:aws:iam::*:role/<YOUR-ADMIN-ROLE>" ] } } } æåŠã®äŸå€æ¡ä»¶ã« ãµãŒãã¹ã«ãªã³ã¯ãããããŒã«ã远å