Mods
AWS

IAM Role: AWS/Directory Service/Metadata

PermissionGrant
ds:CheckAliasMetadata
ds:DescribeCertificateMetadata
ds:DescribeConditionalForwardersMetadata
ds:DescribeDirectoriesMetadata
ds:DescribeDomainControllersMetadata
ds:DescribeEventTopicsMetadata
ds:DescribeLDAPSSettingsMetadata
ds:DescribeSharedDirectoriesMetadata
ds:DescribeSnapshotsMetadata
ds:DescribeTrustsMetadata
ds:GetAuthorizedApplicationDetailsMetadata
ds:GetDirectoryLimitsMetadata
ds:GetSnapshotLimitsMetadata
ds:ListAuthorizedApplicationsMetadata
ds:ListCertificatesMetadata
ds:ListIpRoutesMetadata
ds:ListLogSubscriptionsMetadata
ds:ListSchemaExtensionsMetadata
ds:ListTagsForResourceMetadata
ds:VerifyTrustMetadata
ec2:DescribeNetworkInterfacesMetadata
ec2:DescribeSubnetsMetadata
ec2:DescribeVpcsMetadata
sns:GetTopicAttributesMetadata
sns:ListSubscriptionsMetadata
sns:ListSubscriptionsByTopicMetadata
sns:ListTopicsMetadata