IAM group permissions for iam:AttachUserPolicy need review

Restrict the managed policies that group members can grant to IAM users.

Description

Broad iam:AttachUserPolicy permissions granted through a group can let members attach powerful managed policies to themselves or other IAM users. If attachment is allowed and other limits do not block the resulting access, the target user’s permissions can expand.

The attachment changes the target user’s permissions. It does not automatically bypass permissions boundaries or explicit denies.

Potential impact

  • Members can increase their own resource access without approval.
  • Unnecessary administrative grants to other users can expand an incident’s impact.

Remediation

Remove unnecessary iam:AttachUserPolicy from ordinary groups. Where required, restrict Resource to target user ARNs and use iam:PolicyARN conditions to allow only approved policies. Retain other permission limits and verify intended administration and denial of unapproved attachments.

Examples

This comparison removes policy-attachment permission from an inline policy on the same group. Review actual membership and other attached policies separately.

Before

hcl
resource "aws_iam_group" "example" {
  name = "cosmic"
}

resource "aws_iam_group_policy" "example" {
  name  = "test_inline_policy"
  group = aws_iam_group.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:AttachUserPolicy",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This grants members permission to attach managed policies across users.

After

hcl
resource "aws_iam_group" "example" {
  name = "cosmic"
}

resource "aws_iam_group_policy" "example" {
  name  = "test_inline_policy"
  group = aws_iam_group.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This statement now contains only EC2 describe actions. Check that the same attachment permission does not remain through other policies.

References