IAM role permissions for iam:AttachGroupPolicy need review

Restrict the managed policies and target groups that a role can modify.

Description

A role with iam:AttachGroupPolicy can attach managed policies to permitted IAM groups and expand their users’ permissions. IAM roles are not group members, so the attachment does not directly increase the calling role’s own permissions.

Review the groups and users that could receive powerful policies. Explicit denies and permissions boundaries still apply after attachment.

Potential impact

  • Automation or service roles can unintentionally change several users’ permissions.
  • Misuse of expanded user permissions can increase the risk of information disclosure or resource changes.

Remediation

Remove iam:AttachGroupPolicy where the role does not need it. For required administration, restrict Resource to group ARNs and iam:PolicyARN conditions to approved policy ARNs. Review group membership and change logs, and test intended administration and denial of unapproved attachments.

Examples

These excerpts retain the same role and inline policy. The role’s trust policy is omitted and must be defined separately in the actual configuration.

Before

hcl
resource "aws_iam_role" "example" {
  name = "cosmic"
}

resource "aws_iam_role_policy" "example" {
  name = "test_inline_policy"
  role = aws_iam_role.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:AttachGroupPolicy",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This allows callers using the role to attach policies across groups.

After

hcl
resource "aws_iam_role" "example" {
  name = "cosmic"
}

resource "aws_iam_role_policy" "example" {
  name = "test_inline_policy"
  role = aws_iam_role.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This grant now permits only EC2 describe actions. Review the role’s other permissions; this excerpt is not a complete role configuration.

References