AWS Support policy without an attachment target

Attach support permissions to the identities that need them.

Description

CloudFormation AWS::IAM::Policy attaches an inline policy to roles, users, or groups. At least one target is required, but all three are not. A policy name alone does not select an AWS managed policy.

Potential impact

Without an attachment target, policy deployment can fail and intended support permissions cannot be granted.

Remediation

Specify the appropriate Roles, Users, or Groups responsible for support work, and allow only required actions. Remove unused policies.

Examples

The examples attach a policy allowing only support-case queries to an existing myexistinggroup1 group. The first example, without a target, cannot be deployed.

Before

yaml
Resources:
  noGroups:
    Type: AWS::IAM::Policy
    Properties:
      PolicyName: AWSSupportAccess
      PolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Effect: Allow
            Action: ["support:DescribeCases"]
            Resource: "*"

After

yaml
Resources:
  MyPolicy:
    Type: AWS::IAM::Policy
    Properties:
      PolicyName: mygrouppolicy
      PolicyDocument:
        Version: "2012-10-17"
        Statement:
          - Effect: Allow
            Action:
              - support:DescribeCases
            Resource: "*"
      Groups:
        - myexistinggroup1

References