IAM group permissions for iam:PutGroupPolicy need review

Limit group members’ inline-policy modification permissions to required targets.

Description

Broad iam:PutGroupPolicy permissions granted through an IAM group let members add or replace group inline policies. Granting stronger permissions to a group they belong to can enable privilege escalation.

Group policies apply to their IAM user members. User permissions boundaries, organization policies and explicit denies still limit actual access.

Potential impact

  • One policy change can give several members unnecessary administrative permissions.
  • Unapproved changes can weaken group-based access controls.

Remediation

Remove unnecessary iam:PutGroupPolicy from ordinary groups. Where needed, use a dedicated administration role and an approval process, and restrict Resource to target group ARNs. Review changes, monitor them through CloudTrail, and verify that intended administration works while unapproved changes are blocked.

Examples

This comparison reduces allowed actions in the same group and inline policy.

Before

hcl
resource "aws_iam_group" "example" {
  name = "cosmic"
}

resource "aws_iam_group_policy" "example" {
  name  = "test_inline_policy"
  group = aws_iam_group.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:PutGroupPolicy",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This grants members permission to add or update inline policies across groups.

After

hcl
resource "aws_iam_group" "example" {
  name = "cosmic"
}

resource "aws_iam_group_policy" "example" {
  name  = "test_inline_policy"
  group = aws_iam_group.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This statement now allows only EC2 describe actions. Check for the same modification permission in other policies and review the describe access actually needed.

References