IoT policy allows all resources

Limit AWS IoT permissions to required clients and topics.

Description

Allowing Resource: "*" in an AWS IoT policy broadens the targets of the specified actions. For example, iot:Connect can allow connections using unintended client IDs.

Potential impact

Device isolation can be weakened, or connections using the same client ID can conflict.

Remediation

Specify client, topic or topic filter ARNs appropriate to each action. Define the permitted device IDs and paths, then verify connection and messaging permissions.

Examples

The examples restrict connection permission to client1. Use the resource ARN required by each other IoT action.

Before

yaml
AWSTemplateFormatVersion: 2010-09-09
Description: A sample template
Resources:
  IoTPolicy:
    Type: AWS::IoT::Policy
    Properties:
      PolicyDocument:
        Version: "2012-10-17"
        Statement:
          - Effect: Allow
            Action:
              - iot:Connect
            Resource: "*"
      PolicyName: PolicyName

After

yaml
AWSTemplateFormatVersion: 2010-09-09
Description: A sample template
Resources:
  IoTPolicy:
    Type: AWS::IoT::Policy
    Properties:
      PolicyDocument:
        Version: "2012-10-17"
        Statement:
          - Effect: Allow
            Action:
              - iot:Connect
            Resource:
              - arn:aws:iot:us-east-1:123456789012:client/client1
      PolicyName: PolicyName

References