Managed IAM policy is attached directly to a user

Review managed policies attached directly to users and manage shared permissions consistently.

Description

Attaching a managed IAM policy directly to a user requires tracking that user’s policy associations. Grouping shared permissions can simplify membership changes and access reviews. Direct attachment does not itself make the permissions broader.

Potential impact

Accumulated user-specific exceptions can leave unnecessary permissions in place after responsibilities change or make access removal easier to miss.

Remediation

For shared permissions, attach the managed policy to a group and add approved users to it. Verify required access before removing direct attachments, and document the purpose and review date of user-specific exceptions.

Examples

TestUser and TestGroup are names of existing users and groups. Replace the bucket and object scope with what is actually needed, and associate the user with the group.

Before

yaml
Resources:
  CreateTestDBPolicy:
    Type: "AWS::IAM::ManagedPolicy"
    Properties:
      Description: Read approved S3 objects
      Path: /
      PolicyDocument:
        Version: "2012-10-17"
        Statement:
          - Effect: Allow
            Action: s3:GetObject
            Resource: arn:aws:s3:::example-bucket/*
      Users:
        - TestUser

The managed policy is attached directly to the user.

After

yaml
Resources:
  CreateTestDBPolicy:
    Type: "AWS::IAM::ManagedPolicy"
    Properties:
      Description: Read approved S3 objects
      Path: /
      PolicyDocument:
        Version: "2012-10-17"
        Statement:
          - Effect: Allow
            Action: s3:GetObject
            Resource: arn:aws:s3:::example-bucket/*
      Groups:
        - TestGroup

The same policy is attached to the group. Group membership must be managed separately.

References