Description
An inline policy is embedded in its IAM group and is deleted with that group. Defining the same permissions separately for multiple groups can hinder reuse and central management. An inline policy is not inherently overprivileged.
Potential impact
Duplicated policies can drift or retain outdated permissions. Deleting the group also removes its inline policy, which can complicate recovery and change tracking.
Remediation
Prefer a separate AWS::IAM::ManagedPolicy for reusable permissions. Compare existing permissions and conditions, attach the managed policy, and then remove the inline policy. Verify that required access continues to work.
Examples
The myqueue declaration is omitted. The after excerpt shows only a group without an inline policy; attaching a replacement managed policy is a separate step.
Before
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template
Resources:
myuser:
Type: AWS::IAM::Group
Properties:
Path: "/"
Policies:
- PolicyName: giveaccesstoqueueonly
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- sqs:*
Resource:
- !GetAtt myqueue.Arn
- Effect: Deny
Action:
- sqs:*
NotResource:
- !GetAtt myqueue.Arn
Queue permissions are defined directly in the group’s inline policy.
After
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template
Resources:
myuser:
Type: AWS::IAM::Group
The group has no inline policy. This excerpt alone does not preserve the earlier queue access.