IAM group has no users

Review the purpose and permissions of empty IAM groups and remove those no longer needed.

Description

An IAM group with no users does not itself grant permissions to a user. Unused groups and policies can nevertheless complicate access management and grant unwanted permissions if users are later added by mistake.

Potential impact

Unused permission configurations can make auditing and operations harder. Reusing a group without reviewing its old policies can give new members excessive permissions.

Remediation

Check the group owner, purpose and attached policies. Add only approved users to groups that are needed, and review policies and dependencies before deleting unused groups. Do not add users merely to fill an empty group.

Examples

The myqueue resource and IsSampleIamUser condition declarations are omitted. Review the actual queue permissions separately.

Before

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template 2
Resources:
  myuseeer:
    Type: AWS::IAM::Group
    Properties:
      Path: "/"
      Policies:
        - PolicyName: giveaccesstoqueueonly
          PolicyDocument:
            Version: "2012-10-17"
            Statement:
              - Effect: Allow
                Action:
                  - sqs:*
                Resource:
                  - !GetAtt myqueue.Arn
              - Effect: Deny
                Action:
                  - sqs:*
                NotResource:
                  - !GetAtt myqueue.Arn
  IamUserAdminSample22:
    Type: AWS::IAM::User
    Condition: IsSampleIamUser
    Properties:
      UserName: sample-iam-user-admin

The user has no group association, so the group in this example is empty.

After

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template
Resources:
  myuseeer:
    Type: AWS::IAM::Group
    Properties:
      Path: "/"
      Policies:
        - PolicyName: giveaccesstoqueueonly
          PolicyDocument:
            Version: "2012-10-17"
            Statement:
              - Effect: Allow
                Action:
                  - sqs:*
                Resource:
                  - !GetAtt myqueue.Arn
              - Effect: Deny
                Action:
                  - sqs:*
                NotResource:
                  - !GetAtt myqueue.Arn
  IamUserAdminSample22:
    Type: AWS::IAM::User
    Condition: IsSampleIamUser
    Properties:
      UserName: sample-iam-user-admin
      Groups:
        - !Ref "myuseeer"

When the condition is true, the user is associated with the group. Confirm that the user needs its permissions before making the association.

References