**New actions:**
- connect:AssociateApprovedOrigin
- connect:AssociateInstanceStorageConfig
- connect:AssociateLambdaFunction
- connect:AssociateLexBot
- connect:AssociateSecurityKey
- connect:CreateUserHierarchyGroup
- connect:DeleteInstance
- connect:DeleteUserHierarchyGroup
- connect:DescribeInstanceAttribute
- connect:DescribeInstanceStorageConfig
- connect:DisassociateApprovedOrigin
- connect:DisassociateInstanceStorageConfig
- connect:DisassociateLambdaFunction
- connect:DisassociateLexBot
- connect:DisassociateSecurityKey
- connect:ListApprovedOrigins
- connect:ListInstanceAttributes
- connect:ListInstanceStorageConfigs
- connect:ListLambdaFunctions
- connect:ListLexBots
- connect:ListSecurityKeys
- connect:UpdateInstanceAttribute
- connect:UpdateInstanceStorageConfig
- connect:UpdateUserHierarchyGroupName
- connect:UpdateUserHierarchyStructure
- ec2:AssociateEnclaveCertificateIamRole
- ec2:DisassociateEnclaveCertificateIamRole
- ec2:GetAssociatedEnclaveCertificateIamRoles
- sso-directory:CompleteWebAuthnDeviceRegistration
- sso-directory:StartWebAuthnDeviceRegistration
- sso-directory:UpdateMfaDeviceForUser
**New resource types:**
- acm:certificate
- iam:role
**New conditions:**
- connect:AttributeType
- connect:StorageResourceType
- ec2:Attribute/${ attributeName }
- ec2:ClientRootCertificateChainArn
- ec2:CloudwatchLogGroupArn
- ec2:CloudwatchLogStreamArn
- ec2:DirectoryArn
- ec2:SamlProviderArn
- ec2:ServerCertificateArn