https://aws.amazon.com/blogs/security/how-to-revoke-federated-users-active-aws-sessions/
"Resource":
s3:, lambda:, cloudwatch:, AWSSecretsManagerReadWriteAccess
Advertising: