IAM policy uses wildcards for both actions and resources

Replace blanket IAM action and resource permissions with required access, and verify policy attachments and the active default version.

Description

Combining Action: "*" and Resource: "*" in an IAM allow statement specifies broad permissions across all actions and resources. Remove permissions that exceed the workload's needs. Effective access depends on policy attachments, the default policy version, conditions, explicit denies, permissions boundaries and other controls.

Potential impact

  • When broad permissions take effect, stolen or misused credentials can have a greater impact on data changes, deletion and resource management.
  • Editing a non-default version can leave effective permissions unchanged. Conversely, changing the default version affects every identity attached to the policy.

Remediation

  1. Identify attached users, groups and roles and the current default version. Limit the policy to required service actions and supported resource ARNs. Some actions do not support resource-level restrictions and require Resource: "*"; check support for each action.
  2. Review conditions, explicit denies, permissions boundaries and other policies together. Splitting actions across statements does not itself reduce permissions.
  3. Review the revised version before making it the intended default. Test that required operations still work and prohibited operations are denied.

Examples

These examples do not attach the policy to a user or role. Version: "2012-10-17" identifies the policy language version. Supply the required actual log group ARN in log_group_arn for the after-example.

Before

yaml
- name: Create IAM Managed Policy
  community.aws.iam_managed_policy:
    policy_name: ManagedPolicy
    policy:
      Version: "2012-10-17"
      Statement:
        - Effect: Allow
          Action: "*"
          Resource: "*"
    make_default: false
    state: present

The statement allows all actions on all resources. For an existing policy, make_default: false does not activate the new version automatically; the first version of a newly created policy is its default.

After

yaml
- name: Create IAM Managed Policy
  community.aws.iam_managed_policy:
    policy_name: ManagedPolicy
    policy:
      Version: "2012-10-17"
      Statement:
        - Effect: Allow
          Action: logs:CreateLogGroup
          Resource: "{{ log_group_arn }}"
    make_default: true
    state: present

The policy narrows access to the required log group creation operation and makes this version the default. Check attached identities, required operations and the scope of log_group_arn before applying it.

References