IAM group has excessive iam:CreateLoginProfile permissions

Restrict permission to create other users’ console login profiles.

Description

iam:CreateLoginProfile can set a console password for an IAM user that has no login profile yet. Group members who can do this for a privileged user can create a new access path.

Potential impact

If other sign-in controls permit it, they can gain console access with the target user’s permissions.

Remediation

Remove this permission from groups that do not manage login profiles. Where it is needed, restrict the target users and use dedicated account-administration permissions.

Examples

The examples replace login-profile creation with EC2 describe permissions for the same group. Keep the target user’s other sign-in controls, including MFA.

Before

hcl
resource "aws_iam_group" "example" {
  name = "cosmic"
}

resource "aws_iam_group_policy" "example" {
  name  = "test_inline_policy"
  group = aws_iam_group.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:CreateLoginProfile",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

After

hcl
resource "aws_iam_group" "example" {
  name = "cosmic"
}

resource "aws_iam_group_policy" "example" {
  name = "inline_policy_run_instances"
  group = aws_iam_group.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

References