Description
An IAM Allow statement with both Action: "*" and Resource: "*" expresses broad permissions covering all actions and resources. Effective permissions depend on policy attachments, the default version, conditions, explicit denies and controls such as permissions boundaries.
Remove access that the workload does not need. Splitting a policy into multiple statements alone does not reduce its permissions.
Potential impact
- Where broad permissions apply, stolen or misused credentials can increase the impact on data changes, deletion and resource administration.
- Editing a nondefault version can leave permissions unchanged. Changing the default version affects every attached identity.
Remediation
- Check attached users, groups and roles and the default version. Specify required actions and restrict resource ARNs and conditions where supported.
- Review permission usage and other policies, removing unnecessary read, write and administrative actions.
- Apply the reviewed version as the intended default and test that required operations succeed while unnecessary operations are denied.
Examples
Policy attachments are omitted. Version: "2012-10-17" identifies the policy language version. For an existing policy, a version created with make_default: false does not automatically become the default; a new policy's first version does.
Before
- name: IAM Managed Policy 생성
community.aws.iam_managed_policy:
policy_name: ManagedPolicy
policy:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- "*"
Resource: "*"
make_default: false
state: present
This statement allows all actions on all resources. Check the policies and permission restrictions actually in effect.
After
- name: IAM Managed Policy 생성
community.aws.iam_managed_policy:
policy_name: ManagedPolicy
policy:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action: logs:CreateLogGroup
Resource: "*"
make_default: false
state: present
This statement narrows actions to log group creation, but its resource scope remains broad. Restrict it to required log group ARNs and activate the reviewed policy version.