IAM group permissions for iam:AttachGroupPolicy need review

Limit group members’ permission to attach managed group policies to the required scope.

Description

Broad iam:AttachGroupPolicy permissions granted through an IAM group can let members attach powerful managed policies to groups in the same account. If a target group includes the caller, this can expand the permissions of that user and other members.

Policy conditions, explicit denies, permissions boundaries and organization policies can limit the attachment and resulting permissions.

Potential impact

  • Members can gain resource access that their work does not require.
  • A single group-policy change can affect several IAM users.

Remediation

Remove unnecessary iam:AttachGroupPolicy grants. Where required, restrict Resource to target group ARNs and use iam:PolicyARN conditions to limit the managed policies that can be attached. Use approved administration paths and verify intended operations and denial of unapproved attachments.

Examples

This comparison changes an inline policy on the same group. Check actual group membership separately.

Before

hcl
resource "aws_iam_group" "example" {
  name = "cosmic"
}

resource "aws_iam_group_policy" "example" {
  name  = "test_inline_policy"
  group = aws_iam_group.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:AttachGroupPolicy",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This grants members permission to attach policies across groups.

After

hcl
resource "aws_iam_group" "example" {
  name = "cosmic"
}

resource "aws_iam_group_policy" "example" {
  name  = "test_inline_policy"
  group = aws_iam_group.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This replaces that grant with EC2 describe actions. Check for attachment permissions in other policies and restrict describe access to what is needed.

References