IAM group permissions for iam:PutUserPolicy need review

Restrict group members’ user inline-policy modification permissions.

Description

Broad iam:PutUserPolicy permissions granted to an IAM group let members add or replace inline policies on themselves or other users. This can enable privilege escalation by expanding users’ access when other permission limits do not block it.

Inline policies change the target IAM user’s permissions. They do not automatically remove or bypass boundaries, organization policies or explicit denies.

Potential impact

  • Members can grant administrative permissions to themselves or other users without approval.
  • Misuse of credentials for users with expanded permissions can cause greater damage.

Remediation

Remove unnecessary iam:PutUserPolicy from ordinary groups. Allow required modifications only through approved administration roles and restrict Resource to target user ARNs. Review policy contents and change events, and verify that intended administration works and unapproved changes are blocked.

Examples

This comparison reduces user-policy modification rights in the same group and inline policy.

Before

hcl
resource "aws_iam_group" "example" {
  name = "cosmic"
}

resource "aws_iam_group_policy" "example" {
  name  = "test_inline_policy"
  group = aws_iam_group.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:PutUserPolicy",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This grants members permission to add or update inline policies across users, including themselves.

After

hcl
resource "aws_iam_group" "example" {
  name = "cosmic"
}

resource "aws_iam_group_policy" "example" {
  name  = "test_inline_policy"
  group = aws_iam_group.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This statement now allows only EC2 describe actions. Check for user-modification permissions in other policies and review the describe access needed.

References