Description
The Policies and ManagedPolicyArns properties of AWS::IAM::User attach policies directly to a user. Individual permission management can leave peers with inconsistent access or retain permissions after responsibilities change. Direct attachment is not inherently overprivileged.
Potential impact
Many individual exceptions can complicate access reviews and revocation, making unused permissions easier to overlook.
Remediation
Manage shared IAM user permissions through groups, and prefer roles with temporary credentials for workloads. Verify required access through the replacement path before removing direct attachments. Document the purpose and review date of exceptions that must remain.
Examples
The policy ARNs and myqueue refer to separately prepared resources. Review the queue action scope too. These examples compare attachments only; replacement group or role configuration is omitted.
Before
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template
Resources:
myuser:
Type: AWS::IAM::User
Properties:
Path: "/"
ManagedPolicyArns:
- arn:aws:iam::123456789012:policy/UsersManageOwnCredentials
- arn:aws:iam::123456789012:policy/division_abc/subdivision_xyz/UsersManageOwnCredentials
Policies:
- PolicyName: giveaccesstoqueueonly
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- sqs:*
Resource:
- !GetAtt myqueue.Arn
- Effect: Deny
Action:
- sqs:*
NotResource:
- !GetAtt myqueue.Arn
Managed and inline policies are attached directly to the user.
After
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template
Resources:
myuser:
Type: AWS::IAM::User
Properties:
Path: "/"
Direct policy attachments have been removed. This code alone does not grant access through a group or role.