IAM group has excessive iam:CreateAccessKey permissions

Restrict permission to create other users’ access keys.

Description

Broad iam:CreateAccessKey permission can let group members create and use access keys for other IAM users. Targeting a more privileged user can lead to privilege escalation.

Potential impact

The new credentials can provide access to data and services allowed for the target user.

Remediation

Remove unnecessary key-creation permission. Limit required administration to approved users, and prefer temporary credentials over long-term keys where possible.

Examples

The examples remove key-creation permission and leave the same group with EC2 describe permissions. This does not revoke keys already issued.

Before

hcl
resource "aws_iam_group" "example" {
  name = "cosmic"
}

resource "aws_iam_group_policy" "example" {
  name  = "test_inline_policy"
  group = aws_iam_group.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:CreateAccessKey",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

After

hcl
resource "aws_iam_group" "example" {
  name = "cosmic"
}

resource "aws_iam_group_policy" "example" {
  name = "inline_policy_run_instances"
  group = aws_iam_group.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

References