IAM policy allows full privileges

Limit IAM policy actions and resources to the required scope.

Description

Using Allow with Action: "*" and Resource: "*" in an IAM policy grants broad permissions across all actions and resources. Conditions and other limiting policies still affect effective access.

Potential impact

A compromised account or workload with the policy can have a broad impact on data and service configuration.

Remediation

Specify the required actions and resource ARNs. Put actions that do not support resource-level permissions in separate statements with appropriate conditions.

Examples

The examples narrow access to objects in a particular S3 bucket. Replace the bucket and attached groups with actual values, and retain object ACL modification permission only if needed.

Before

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template
Resources:
  mypolicy:
    Type: AWS::IAM::Policy
    Properties:
      PolicyName: mygrouppolicy
      PolicyDocument:
        Version: "2012-10-17"
        Statement:
          - Effect: Allow
            Action: ["*"]
            Resource: "*"
      Groups:
        - myexistinggroup1
        - !Ref mygroup

After

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template
Resources:
  MyPolicy:
    Type: AWS::IAM::Policy
    Properties:
      PolicyName: mygrouppolicy
      PolicyDocument:
        Version: "2012-10-17"
        Statement:
          - Effect: Allow
            Action:
              - s3:GetObject
              - s3:PutObject
              - s3:PutObjectAcl
            Resource: arn:aws:s3:::myAWSBucket/*
      Groups:
        - myexistinggroup1
        - !Ref mygroup

References