Description
A role with iam:AttachGroupPolicy can attach managed policies to permitted IAM groups and expand their users’ permissions. IAM roles are not group members, so the attachment does not directly increase the calling role’s own permissions.
Review the groups and users that could receive powerful policies. Explicit denies and permissions boundaries still apply after attachment.
Potential impact
- Automation or service roles can unintentionally change several users’ permissions.
- Misuse of expanded user permissions can increase the risk of information disclosure or resource changes.
Remediation
Remove iam:AttachGroupPolicy where the role does not need it. For required administration, restrict Resource to group ARNs and iam:PolicyARN conditions to approved policy ARNs. Review group membership and change logs, and test intended administration and denial of unapproved attachments.
Examples
These excerpts retain the same role and inline policy. The role’s trust policy is omitted and must be defined separately in the actual configuration.
Before
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "test_inline_policy"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:AttachGroupPolicy",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This allows callers using the role to attach policies across groups.
After
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "test_inline_policy"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This grant now permits only EC2 describe actions. Review the role’s other permissions; this excerpt is not a complete role configuration.