IoT policy allows all actions

List only the AWS IoT actions the device actually needs.

Description

Allowing Action: "*" in an AWS IoT policy broadly permits supported actions within the policy’s resource scope.

Potential impact

Unneeded device permissions can increase the impact of malfunction or compromised credentials.

Remediation

Specify only required actions, such as connecting, publishing or subscribing, and use the appropriate resource scope for each action.

Examples

The examples explicitly grant iot:Connect for a particular client. Actions and resources jointly determine access, so configure the actual client ID.

Before

yaml
AWSTemplateFormatVersion: 2010-09-09
Description: A sample template
Resources:
  IoTPolicy:
    Type: AWS::IoT::Policy
    Properties:
      PolicyDocument:
        Version: "2012-10-17"
        Statement:
          - Effect: Allow
            Action: "*"
            Resource:
              - arn:aws:iot:us-east-1:123456789012:client/client
      PolicyName: PolicyName

After

yaml
AWSTemplateFormatVersion: 2010-09-09
Description: A sample template
Resources:
  IoTPolicy:
    Type: AWS::IoT::Policy
    Properties:
      PolicyDocument:
        Version: "2012-10-17"
        Statement:
          - Effect: Allow
            Action:
              - iot:Connect
            Resource:
              - arn:aws:iot:us-east-1:123456789012:client/client1
      PolicyName: PolicyName

References