Review IAM group membership

Check actual IAM group membership and purpose, and remove unnecessary permission configurations.

Description

IAM groups apply shared permissions to users. A group without users may be awaiting use or may be obsolete. An empty group cannot exercise permissions or cause privilege escalation by itself.

Confirm the group's owner and purpose, and manage its actual users and attached policies. Omitting the user list from configuration does not remove existing members.

Potential impact

  • Accumulated unused groups and policies make permission audits and changes harder to manage.
  • Adding users to an old group can grant permissions they do not need.

Remediation

  1. Check actual group members and attached policies, and document the group's purpose.
  2. Add only IAM users who need those permissions and limit access to their work. Do not add users merely to fill an empty group.
  3. Review dependencies and policies before deleting unused groups. When reconciling membership, check the effect of purge_users and retain required users.

Examples

These examples omit or specify membership on different groups. Select the actual users and policies. The current module name is amazon.aws.iam_group.

Before

yaml
- name: IAM 그룹 생성
  iam_group:
    name: testgroup1
    state: present

This creates or retains a group without adding users. For an existing group, check its current membership separately.

After

yaml
- name: IAM 그룹 생성
  iam_group:
    name: testgroup2
    managed_policy:
      - arn:aws:iam::aws:policy/AmazonSNSFullAccess
    users:
      - test_user1
      - test_user2
    state: present

This adds the named users to another group. Review whether AmazonSNSFullAccess is needed. Membership alone does not ensure least privilege or clean up the first group.

References