IAM group permissions for iam:PutRolePolicy need review

Restrict the role inline policies that group members can modify.

Description

Broad iam:PutRolePolicy permissions granted through a group let members add or update role inline policies. Members can use expanded permissions if they can assume the modified role or control a workload running with it.

Updating a role policy does not change its trust policy or grant permission to assume it. The target role’s boundaries, organization policies and explicit denies still apply.

Potential impact

  • Services using a role can gain resource access they do not need.
  • Unapproved role policy changes can affect the execution permissions of several workloads.

Remediation

Remove unnecessary iam:PutRolePolicy from ordinary groups. Perform required changes through approved administration roles and restrict Resource to target role ARNs. Review role-use paths and policy contents, and test that intended work succeeds while unapproved changes are blocked.

Examples

This comparison reduces role-policy modification rights in the same group and inline policy.

Before

hcl
resource "aws_iam_group" "example" {
  name = "cosmic"
}

resource "aws_iam_group_policy" "example" {
  name  = "test_inline_policy"
  group = aws_iam_group.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:PutRolePolicy",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This grants members permission to add or update inline policies across roles.

After

hcl
resource "aws_iam_group" "example" {
  name = "cosmic"
}

resource "aws_iam_group_policy" "example" {
  name  = "test_inline_policy"
  group = aws_iam_group.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This narrows the statement to EC2 describe actions. Review role-modification rights in other policies and whether the describe actions are needed.

References