IAM role permissions for iam:PutGroupPolicy need review

Restrict the group inline policies that a role can modify.

Description

Callers using a role with iam:PutGroupPolicy can add or replace inline policies on target groups, expanding their IAM user members’ permissions. This administrative permission can grant unnecessary access to several users.

IAM roles cannot be group members, so this does not directly expand the calling role’s own permissions. Target users’ boundaries, organization policies and explicit denies still limit actual access.

Potential impact

  • Incorrect changes by an automation role can give several users excessive permissions.
  • Unapproved group policy changes can weaken access controls within the account.

Remediation

Remove iam:PutGroupPolicy where the role does not need it. Grant required modifications through approved administration roles and restrict Resource to target group ARNs. Review policy contents and change history, and test that intended administration works and unapproved changes are blocked.

Examples

These excerpts retain the same role and inline policy. Define the omitted role trust policy separately in the actual configuration.

Before

hcl
resource "aws_iam_role" "example" {
  name = "cosmic"
}

resource "aws_iam_role_policy" "example" {
  name = "test_inline_policy"
  role = aws_iam_role.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:PutGroupPolicy",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

Callers using this role can add or update inline policies across groups.

After

hcl
resource "aws_iam_role" "example" {
  name = "cosmic"
}

resource "aws_iam_role_policy" "example" {
  name = "test_inline_policy"
  role = aws_iam_role.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This narrows the statement to EC2 describe actions. Review other group-administration permissions and unnecessary describe access.

References