Description
Attaching the same permissions directly to multiple IAM users can make individual attachments easy to miss during changes or revocation. Group policies help manage permissions for users performing the same duties.
Potential impact
Per-user permissions can remain after duties change, or make access reviews harder.
Remediation
Attach shared permissions through Groups in AWS::IAM::Policy and manage user membership. Review necessary user-specific exceptions and remove direct attachments that have been migrated.
Examples
These excerpts attach the same queue policy through Groups instead of Users. Prepare the existing users, group, and myqueue separately.
Before
yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: Policy attachment comparison
Resources:
myuser:
Type: AWS::IAM::Policy
Properties:
PolicyName: giveaccesstoqueueonly
PolicyDocument:
Version: '2012-10-17'
Statement:
- Effect: Allow
Action:
- sqs:*
Resource:
- !GetAtt myqueue.Arn
- Effect: Deny
Action:
- sqs:*
NotResource:
- !GetAtt myqueue.Arn
Users:
- existinguser1
- existinguser2
After
yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: Policy attachment comparison
Resources:
myuser:
Type: AWS::IAM::Policy
Properties:
PolicyName: giveaccesstoqueueonly
PolicyDocument:
Version: '2012-10-17'
Statement:
- Effect: Allow
Action:
- sqs:*
Resource:
- !GetAtt myqueue.Arn
- Effect: Deny
Action:
- sqs:*
NotResource:
- !GetAtt myqueue.Arn
Groups:
- myexistinggroup1