IAM group permissions for iam:AttachRolePolicy need review

Restrict the roles and managed policies that group members can modify.

Description

Group members with broad iam:AttachRolePolicy permissions can attach powerful managed policies to roles. They can use the expanded permissions if they can assume a target role or control a workload using it.

Attaching a policy does not change the role’s trust policy or itself grant permission to assume the role. Other permission limits also apply to attachment and subsequent actions.

Potential impact

  • Services or user sessions can receive more role permissions than they need.
  • An unapproved attachment can affect several workloads that use a role.

Remediation

Remove unnecessary iam:AttachRolePolicy from the group. Where needed, specify target role ARNs in Resource and limit managed policies with iam:PolicyARN conditions. Review role-assumption and workload-control permissions, and test intended operations and denial of unapproved attachments.

Examples

This comparison preserves the same group and inline policy. It reduces permissions for members who do not need to administer roles.

Before

hcl
resource "aws_iam_group" "example" {
  name = "cosmic"
}

resource "aws_iam_group_policy" "example" {
  name  = "test_inline_policy"
  group = aws_iam_group.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:AttachRolePolicy",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This grants members permission to attach managed policies across roles.

After

hcl
resource "aws_iam_group" "example" {
  name = "cosmic"
}

resource "aws_iam_group_policy" "example" {
  name  = "test_inline_policy"
  group = aws_iam_group.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This statement now contains only EC2 describe actions. Review role-administration grants in other policies and the describe access actually needed.

References