IAM group permissions for iam:AddUserToGroup need review

Restrict which IAM groups members can add users to.

Description

Broad iam:AddUserToGroup permissions granted through a group let members add themselves or other IAM users to other groups in the same account. This can enable privilege escalation if the target group grants greater effective permissions.

Resource identifies the target group ARN. Restricting target groups alone does not restrict which user can be added, so approve both the user and the destination group. Permissions boundaries, organization policies and explicit denies can still limit the added user’s access.

Potential impact

  • Unapproved users can gain the access granted by a more privileged group.
  • Granting access through membership changes can bypass the established approval process.

Remediation

Remove unnecessary iam:AddUserToGroup from ordinary groups and manage membership through approved administration roles. Restrict Resource to approved target group ARNs and review the users being added. Test that required changes work and unapproved additions are blocked, and review membership-change logs.

Examples

This comparison removes user-addition permission from an inline policy on the same group.

Before

hcl
resource "aws_iam_group" "example" {
  name = "cosmic"
}

resource "aws_iam_group_policy" "example" {
  name  = "test_inline_policy"
  group = aws_iam_group.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:AddUserToGroup",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This grants group members permission to add users to groups throughout the account.

After

hcl
resource "aws_iam_group" "example" {
  name = "cosmic"
}

resource "aws_iam_group_policy" "example" {
  name  = "test_inline_policy"
  group = aws_iam_group.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This restricts the statement to EC2 describe actions. Review membership-management rights in other policies and the describe scope.

References