
On the group page CostTest.
In the Filter box, click Type.


Customer managed are the IAM Policies we create and manage ourselves.
Click the Filter box, enter the name of the policy we created in the previous step ( EC2_FamilyRestrict ).
Click the checkbox next to EC2_FamilyRestrict policy.



We need to remove the RegionRestrict policy because this policy provides full permissions on the EC2 service.
Next step, we will log in with user testuser to check if we can create an EC2 server with a family other than T3.