I am administering one AWS account. Now one of my non-privileged users ask me to give him rights to create IAM Roles. I understand that IAM Roles usually best choice, but I afraid that they will be able to create "Role for Cross-Account Access" and allow someone else access to my AWS account.
This is possibly to give access only create "AWS Service Roles", but not "Role for Cross-Account Access" ?