Description
Combining Action: "*" and Resource: "*" in an IAM allow statement specifies broad permissions across all actions and resources. Remove permissions that exceed the workload's needs. Effective access depends on policy attachments, the default policy version, conditions, explicit denies, permissions boundaries and other controls.
Potential impact
- When broad permissions take effect, stolen or misused credentials can have a greater impact on data changes, deletion and resource management.
- Editing a non-default version can leave effective permissions unchanged. Conversely, changing the default version affects every identity attached to the policy.
Remediation
- Identify attached users, groups and roles and the current default version. Limit the policy to required service actions and supported resource ARNs. Some actions do not support resource-level restrictions and require
Resource: "*"; check support for each action. - Review conditions, explicit denies, permissions boundaries and other policies together. Splitting actions across statements does not itself reduce permissions.
- Review the revised version before making it the intended default. Test that required operations still work and prohibited operations are denied.
Examples
These examples do not attach the policy to a user or role. Version: "2012-10-17" identifies the policy language version. Supply the required actual log group ARN in log_group_arn for the after-example.
Before
- name: Create IAM Managed Policy
community.aws.iam_managed_policy:
policy_name: ManagedPolicy
policy:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action: "*"
Resource: "*"
make_default: false
state: present
The statement allows all actions on all resources. For an existing policy, make_default: false does not activate the new version automatically; the first version of a newly created policy is its default.
After
- name: Create IAM Managed Policy
community.aws.iam_managed_policy:
policy_name: ManagedPolicy
policy:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action: logs:CreateLogGroup
Resource: "{{ log_group_arn }}"
make_default: true
state: present
The policy narrows access to the required log group creation operation and makes this version the default. Check attached identities, required operations and the scope of log_group_arn before applying it.