Description
An account ARN in a role trust policy’s Principal delegates authority to that account. The ARN’s root suffix does not mean only the root user; identities granted permission in that account can also assume the role.
Potential impact
Excessive delegation can allow unintended identities in the trusted account to use the role’s permissions.
Remediation
Specify required role or service principals, or apply appropriate limiting conditions. If account-wide delegation is needed, check which identities in that account receive permission to assume the role.
Examples
The examples narrow trust from an account to a specific role. Specify actual account and role ARNs.
Before
yaml
AWSTemplateFormatVersion: "2010-09-09"
Resources:
RootRole:
Type: "AWS::IAM::Role"
Properties:
AssumeRolePolicyDocument: >
{
"Version": "2012-10-17",
"Statement": [
{
"Action": "sts:AssumeRole",
"Principal": {
"AWS": "arn:aws:iam::111122223333:root"
},
"Effect": "Allow",
"Sid": ""
}
]
}
After
yaml
AWSTemplateFormatVersion: "2010-09-09"
Resources:
ApplicationRole:
Type: "AWS::IAM::Role"
Properties:
AssumeRolePolicyDocument:
Version: "2012-10-17"
Statement:
- Action: "sts:AssumeRole"
Effect: "Allow"
Principal:
AWS: "arn:aws:iam::111122223333:role/TrustedApplicationRole"