IAM policy attached directly to users

Check whether shared permissions can be managed through a group.

Description

Attaching the same permissions directly to multiple IAM users can make individual attachments easy to miss during changes or revocation. Group policies help manage permissions for users performing the same duties.

Potential impact

Per-user permissions can remain after duties change, or make access reviews harder.

Remediation

Attach shared permissions through Groups in AWS::IAM::Policy and manage user membership. Review necessary user-specific exceptions and remove direct attachments that have been migrated.

Examples

These excerpts attach the same queue policy through Groups instead of Users. Prepare the existing users, group, and myqueue separately.

Before

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: Policy attachment comparison
Resources:
    myuser:
      Type: AWS::IAM::Policy
      Properties:
        PolicyName: giveaccesstoqueueonly
        PolicyDocument:
          Version: '2012-10-17'
          Statement:
          - Effect: Allow
            Action:
            - sqs:*
            Resource:
            - !GetAtt myqueue.Arn
          - Effect: Deny
            Action:
            - sqs:*
            NotResource:
            - !GetAtt myqueue.Arn
        Users:
          - existinguser1
          - existinguser2

After

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: Policy attachment comparison
Resources:
    myuser:
      Type: AWS::IAM::Policy
      Properties:
        PolicyName: giveaccesstoqueueonly
        PolicyDocument:
          Version: '2012-10-17'
          Statement:
          - Effect: Allow
            Action:
            - sqs:*
            Resource:
            - !GetAtt myqueue.Arn
          - Effect: Deny
            Action:
            - sqs:*
            NotResource:
            - !GetAtt myqueue.Arn
        Groups:
          - myexistinggroup1

References