- S3 403 Access Denied responses now include the ARN of the IAM or Organizations policy that caused the denial.
- The ARN is provided for explicit deny cases across all policy types (SCP, RCP, identity, session, permission boundaries) in all regions.
- Enables faster identification and remediation of the specific policy responsible for a denied request.