IAM policy attached directly to a user

Manage shared IAM permissions through groups or roles.

Description

Attaching policies directly to individual users can scatter permission management across users. Manage shared permissions through groups or roles, and keep user-specific exceptions only when needed.

Potential impact

Many directly attached exceptions make it harder to understand why permissions were granted and which ones should be removed after changes.

Remediation

Review directly attached user policies and move shared permissions to suitable groups or roles. Changing the attachment does not reduce the permissions themselves; also limit the policy to required actions and resources.

Examples

The examples move the same policy from a user to a group. Narrow its broad example permissions for production, and define the user and group separately. aws_iam_policy_attachment exclusively manages all attachments of that policy.

Before

hcl
resource "aws_iam_policy_attachment" "example" {
  name = "excess_policy"
  users = [aws_iam_user.user.name]
  policy_arn = aws_iam_policy.example.arn
}

resource "aws_iam_policy" "example" {
  name = "excess_policy"

  policy = <<EOF
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Action": [
        "ec2:*",
        "s3:*",
        "lambda:*",
        "cloudwatch:*"
      ],
      "Effect": "Allow",
      "Resource": "*"
    }
  ]
}
EOF
}

After

hcl
resource "aws_iam_policy_attachment" "example" {
  name = "excess_policy"
  groups = [aws_iam_group.group.name]
  policy_arn = aws_iam_policy.example.arn
}

resource "aws_iam_policy" "example" {
  name = "excess_policy"

  policy = <<EOF
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Action": [
        "ec2:*",
        "s3:*",
        "lambda:*",
        "cloudwatch:*"
      ],
      "Effect": "Allow",
      "Resource": "*"
    }
  ]
}
EOF
}

References