Description
Attaching a managed IAM policy directly to a user requires tracking that user’s policy associations. Grouping shared permissions can simplify membership changes and access reviews. Direct attachment does not itself make the permissions broader.
Potential impact
Accumulated user-specific exceptions can leave unnecessary permissions in place after responsibilities change or make access removal easier to miss.
Remediation
For shared permissions, attach the managed policy to a group and add approved users to it. Verify required access before removing direct attachments, and document the purpose and review date of user-specific exceptions.
Examples
TestUser and TestGroup are names of existing users and groups. Replace the bucket and object scope with what is actually needed, and associate the user with the group.
Before
Resources:
CreateTestDBPolicy:
Type: "AWS::IAM::ManagedPolicy"
Properties:
Description: Read approved S3 objects
Path: /
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action: s3:GetObject
Resource: arn:aws:s3:::example-bucket/*
Users:
- TestUser
The managed policy is attached directly to the user.
After
Resources:
CreateTestDBPolicy:
Type: "AWS::IAM::ManagedPolicy"
Properties:
Description: Read approved S3 objects
Path: /
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action: s3:GetObject
Resource: arn:aws:s3:::example-bucket/*
Groups:
- TestGroup
The same policy is attached to the group. Group membership must be managed separately.