Description
IAM groups apply shared permissions to users. A group without users may be awaiting use or may be obsolete. An empty group cannot exercise permissions or cause privilege escalation by itself.
Confirm the group's owner and purpose, and manage its actual users and attached policies. Omitting the user list from configuration does not remove existing members.
Potential impact
- Accumulated unused groups and policies make permission audits and changes harder to manage.
- Adding users to an old group can grant permissions they do not need.
Remediation
- Check actual group members and attached policies, and document the group's purpose.
- Add only IAM users who need those permissions and limit access to their work. Do not add users merely to fill an empty group.
- Review dependencies and policies before deleting unused groups. When reconciling membership, check the effect of
purge_usersand retain required users.
Examples
These examples omit or specify membership on different groups. Select the actual users and policies. The current module name is amazon.aws.iam_group.
Before
- name: IAM 그룹 생성
iam_group:
name: testgroup1
state: present
This creates or retains a group without adding users. For an existing group, check its current membership separately.
After
- name: IAM 그룹 생성
iam_group:
name: testgroup2
managed_policy:
- arn:aws:iam::aws:policy/AmazonSNSFullAccess
users:
- test_user1
- test_user2
state: present
This adds the named users to another group. Review whether AmazonSNSFullAccess is needed. Membership alone does not ensure least privilege or clean up the first group.