Improve scoping of access controls
Pre-release
Pre-release
This release improves scoping of the access controls:
- The DenyEveryoneElse statement scopes its coverage to the account's IAM users instead of all IAM principals, enabling use provisioned by an AWS service via KMS key grants, e.g. DynamoDB
- Use Like within the Deny when an Allow statement has done so