IAM group uses an inline policy

Use managed policies to reuse common IAM group permissions and manage changes consistently.

Description

An inline policy is embedded in its IAM group and is deleted with that group. Defining the same permissions separately for multiple groups can hinder reuse and central management. An inline policy is not inherently overprivileged.

Potential impact

Duplicated policies can drift or retain outdated permissions. Deleting the group also removes its inline policy, which can complicate recovery and change tracking.

Remediation

Prefer a separate AWS::IAM::ManagedPolicy for reusable permissions. Compare existing permissions and conditions, attach the managed policy, and then remove the inline policy. Verify that required access continues to work.

Examples

The myqueue declaration is omitted. The after excerpt shows only a group without an inline policy; attaching a replacement managed policy is a separate step.

Before

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template
Resources:
  myuser:
    Type: AWS::IAM::Group
    Properties:
      Path: "/"
      Policies:
        - PolicyName: giveaccesstoqueueonly
          PolicyDocument:
            Version: "2012-10-17"
            Statement:
              - Effect: Allow
                Action:
                  - sqs:*
                Resource:
                  - !GetAtt myqueue.Arn
              - Effect: Deny
                Action:
                  - sqs:*
                NotResource:
                  - !GetAtt myqueue.Arn

Queue permissions are defined directly in the group’s inline policy.

After

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template
Resources:
  myuser:
    Type: AWS::IAM::Group

The group has no inline policy. This excerpt alone does not preserve the earlier queue access.

References