Review account-wide trust in an IAM role

Check that account delegation in the role trust policy matches the intended scope.

Description

An account ARN in a role trust policy’s Principal delegates authority to that account. The ARN’s root suffix does not mean only the root user; identities granted permission in that account can also assume the role.

Potential impact

Excessive delegation can allow unintended identities in the trusted account to use the role’s permissions.

Remediation

Specify required role or service principals, or apply appropriate limiting conditions. If account-wide delegation is needed, check which identities in that account receive permission to assume the role.

Examples

The examples narrow trust from an account to a specific role. Specify actual account and role ARNs.

Before

yaml
AWSTemplateFormatVersion: "2010-09-09"
Resources:
  RootRole:
    Type: "AWS::IAM::Role"
    Properties:
      AssumeRolePolicyDocument: >
        {
            "Version": "2012-10-17",
            "Statement": [
                {
                    "Action": "sts:AssumeRole",
                    "Principal": {
                        "AWS": "arn:aws:iam::111122223333:root"
                    },
                    "Effect": "Allow",
                    "Sid": ""
                }
            ]
        }

After

yaml
AWSTemplateFormatVersion: "2010-09-09"
Resources:
  ApplicationRole:
    Type: "AWS::IAM::Role"
    Properties:
      AssumeRolePolicyDocument:
        Version: "2012-10-17"
        Statement:
          - Action: "sts:AssumeRole"
            Effect: "Allow"
            Principal:
              AWS: "arn:aws:iam::111122223333:role/TrustedApplicationRole"

References