Description
An IAM group with no users does not itself grant permissions to a user. Unused groups and policies can nevertheless complicate access management and grant unwanted permissions if users are later added by mistake.
Potential impact
Unused permission configurations can make auditing and operations harder. Reusing a group without reviewing its old policies can give new members excessive permissions.
Remediation
Check the group owner, purpose and attached policies. Add only approved users to groups that are needed, and review policies and dependencies before deleting unused groups. Do not add users merely to fill an empty group.
Examples
The myqueue resource and IsSampleIamUser condition declarations are omitted. Review the actual queue permissions separately.
Before
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template 2
Resources:
myuseeer:
Type: AWS::IAM::Group
Properties:
Path: "/"
Policies:
- PolicyName: giveaccesstoqueueonly
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- sqs:*
Resource:
- !GetAtt myqueue.Arn
- Effect: Deny
Action:
- sqs:*
NotResource:
- !GetAtt myqueue.Arn
IamUserAdminSample22:
Type: AWS::IAM::User
Condition: IsSampleIamUser
Properties:
UserName: sample-iam-user-admin
The user has no group association, so the group in this example is empty.
After
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template
Resources:
myuseeer:
Type: AWS::IAM::Group
Properties:
Path: "/"
Policies:
- PolicyName: giveaccesstoqueueonly
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- sqs:*
Resource:
- !GetAtt myqueue.Arn
- Effect: Deny
Action:
- sqs:*
NotResource:
- !GetAtt myqueue.Arn
IamUserAdminSample22:
Type: AWS::IAM::User
Condition: IsSampleIamUser
Properties:
UserName: sample-iam-user-admin
Groups:
- !Ref "myuseeer"
When the condition is true, the user is associated with the group. Confirm that the user needs its permissions before making the association.