Review account principals in IAM policies

Review account principals in IAM policies and the intended scope of role trust.

Description

An account ARN such as arn:aws:iam::123456789012:root in a role trust policy delegates authority to that account; it does not mean only its root user. The account administrator can delegate access to users or roles with the required permissions. It does not unconditionally allow every AWS account or user to assume the role.

If only a particular role should be trusted, restrict trust to its ARN and appropriate conditions. IAM managed policies cannot use Principal, so distinguish permission policies from role trust policies.

Potential impact

  • Account delegation broader than intended can allow additional identities to use the role as that account's permissions change.
  • Excessive role permissions can increase the impact of mistaken delegation or credential misuse.

Remediation

  1. Determine whether account-level delegation is needed. If only a specific identity needs access, specify its approved role ARN in the trust policy's Principal.
  2. Review cross-account caller permissions and trust conditions together, and minimize the role's permissions. Account delegation is not inherently wrong; assess it against operational requirements.
  3. Remove unnecessary trust relationships and test successful legitimate assumptions and rejection of unapproved requests.

Examples

The first example is invalid because it places Principal in a managed policy. The second uses the correct policy type to trust a specific role. Replace the account and role ARN with approved values and configure caller and target-role permissions separately.

Before

yaml
- name: IAM 정책 생성
  community.aws.iam_managed_policy:
    policy_name: ManagedPolicy
    policy:
      Version: "2012-10-17"
      Statement:
        - Effect: Allow
          Action: logs:CreateLogGroup
          Resource: "*"
          Principal:
            AWS: arn:aws:iam::123456789012:root
    make_default: false
    state: present

This configuration does not create valid role trust. The same account ARN, when used in a trust policy, delegates authority to that account.

After

yaml
- name: Configure trust for an approved role
  amazon.aws.iam_role:
    name: log-writer-target-role
    assume_role_policy_document: >
      {
        "Version": "2012-10-17",
        "Statement": [
          {
            "Effect": "Allow",
            "Action": "sts:AssumeRole",
            "Principal": {
              "AWS": "arn:aws:iam::123456789012:role/log-writer-role"
            }
          }
        ]
      }
    state: present

This trust statement targets only the specified role. Review other trust statements and caller permissions as well.

References