IAM policies are attached directly to a user

Review permissions attached directly to IAM users and manage shared access through groups or roles.

Description

The Policies and ManagedPolicyArns properties of AWS::IAM::User attach policies directly to a user. Individual permission management can leave peers with inconsistent access or retain permissions after responsibilities change. Direct attachment is not inherently overprivileged.

Potential impact

Many individual exceptions can complicate access reviews and revocation, making unused permissions easier to overlook.

Remediation

Manage shared IAM user permissions through groups, and prefer roles with temporary credentials for workloads. Verify required access through the replacement path before removing direct attachments. Document the purpose and review date of exceptions that must remain.

Examples

The policy ARNs and myqueue refer to separately prepared resources. Review the queue action scope too. These examples compare attachments only; replacement group or role configuration is omitted.

Before

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template
Resources:
  myuser:
    Type: AWS::IAM::User
    Properties:
      Path: "/"
      ManagedPolicyArns:
        - arn:aws:iam::123456789012:policy/UsersManageOwnCredentials
        - arn:aws:iam::123456789012:policy/division_abc/subdivision_xyz/UsersManageOwnCredentials
      Policies:
        - PolicyName: giveaccesstoqueueonly
          PolicyDocument:
            Version: "2012-10-17"
            Statement:
              - Effect: Allow
                Action:
                  - sqs:*
                Resource:
                  - !GetAtt myqueue.Arn
              - Effect: Deny
                Action:
                  - sqs:*
                NotResource:
                  - !GetAtt myqueue.Arn

Managed and inline policies are attached directly to the user.

After

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template
Resources:
  myuser:
    Type: AWS::IAM::User
    Properties:
      Path: "/"

Direct policy attachments have been removed. This code alone does not grant access through a group or role.

References