Description
An IAM allow policy covering all actions and all resources can grant permissions far beyond a workload’s needs. Limit access to the required operations and resources to reduce the impact of compromised credentials or operational mistakes.
Explicit denies, permissions boundaries and organization policies also affect actual requests. Some actions do not support resource-level restrictions; limit those actions and use applicable conditions.
Potential impact
- Compromised credentials may allow unnecessary data access, modification or resource deletion.
- Excessive administrative permissions can increase harm through security-setting changes or further permission grants.
Remediation
- Replace all-action grants with the required action list and restrict supported actions to resource ARNs.
- Separate permissions by purpose and remove unnecessary grants based on usage records and business requirements.
- Verify that required operations succeed and unapproved operations are denied after the change.
Examples
These excerpts narrow the same user policy. Define the referenced IAM user and S3 bucket separately. Review additional permissions separately if the workload needs more than object reads.
Before
resource "aws_iam_user_policy" "full_access_policy" {
name = "excess_policy"
user = aws_iam_user.user.name
policy = <<EOF
{
"Version": "2012-10-17",
"Statement": [
{
"Action": [
"*"
],
"Effect": "Allow",
"Resource": "*"
}
]
}
EOF
}
This grants Allow for all actions and resources. Remove unnecessary broad grants even when other controls limit their effect.
After
resource "aws_iam_user_policy" "full_access_policy" {
name = "excess_policy"
user = aws_iam_user.user.name
policy = <<EOF
{
"Version": "2012-10-17",
"Statement": [
{
"Action": [
"s3:GetObject"
],
"Effect": "Allow",
"Resource": "${aws_s3_bucket.app_data.arn}/*"
}
]
}
EOF
}
This limits the same policy to reading objects in the specified bucket. This statement does not grant bucket listing or writes.