Due to recent AWS changes, you might need to add additional permissions to the relevant IAM policies.
Action required
We are updating Amazon EFS such that a principal applying tags to an EFS
resource on creation (For example, a file system or an access point) must have
IAM permissions to apply tags to the resources using the TagResource operation.
If a principal attempts to create an EFS resource with tags and does not have
permission to add tags, the resource creation will not succeed. For this
account, this change will go into effect on June 30, 2023.
Solution: