Description
Attaching policies directly to individual users can scatter permission management across users. Manage shared permissions through groups or roles, and keep user-specific exceptions only when needed.
Potential impact
Many directly attached exceptions make it harder to understand why permissions were granted and which ones should be removed after changes.
Remediation
Review directly attached user policies and move shared permissions to suitable groups or roles. Changing the attachment does not reduce the permissions themselves; also limit the policy to required actions and resources.
Examples
The examples move the same policy from a user to a group. Narrow its broad example permissions for production, and define the user and group separately. aws_iam_policy_attachment exclusively manages all attachments of that policy.
Before
resource "aws_iam_policy_attachment" "example" {
name = "excess_policy"
users = [aws_iam_user.user.name]
policy_arn = aws_iam_policy.example.arn
}
resource "aws_iam_policy" "example" {
name = "excess_policy"
policy = <<EOF
{
"Version": "2012-10-17",
"Statement": [
{
"Action": [
"ec2:*",
"s3:*",
"lambda:*",
"cloudwatch:*"
],
"Effect": "Allow",
"Resource": "*"
}
]
}
EOF
}
After
resource "aws_iam_policy_attachment" "example" {
name = "excess_policy"
groups = [aws_iam_group.group.name]
policy_arn = aws_iam_policy.example.arn
}
resource "aws_iam_policy" "example" {
name = "excess_policy"
policy = <<EOF
{
"Version": "2012-10-17",
"Statement": [
{
"Action": [
"ec2:*",
"s3:*",
"lambda:*",
"cloudwatch:*"
],
"Effect": "Allow",
"Resource": "*"
}
]
}
EOF
}