Identity Center permission set grants excessive access

Restrict the permission set to the needs of its assigned accounts and users.

Description

An IAM Identity Center permission set allowing every action and resource can grant assigned users and groups more access than their work requires. Deploying the same set across accounts increases the impact of changes.

Actual access also depends on account assignments, other attached policies, permissions boundaries and organization policies. The policy does not automatically grant access to every SSO user or the entire organization.

Potential impact

  • A compromised or misused session may permit unnecessary data access, modification or administration.
  • An overprivileged set assigned to multiple accounts can spread the impact of the same mistake.

Remediation

  • Limit the set to required actions and resource ARNs, and assign administrative access only to those who need it.
  • Review other policies in the permission set and actual user, group and account assignments together.
  • Apply changes to the required accounts and verify that normal work succeeds while unapproved actions are denied.

Examples

These excerpts narrow the same permission set’s inline policy. Configure the permission set and account assignments separately, and replace the example bucket ARNs with approved buckets.

Before

hcl
resource "aws_ssoadmin_permission_set_inline_policy" "example" {
  instance_arn       = aws_ssoadmin_permission_set.example.instance_arn
  permission_set_arn = aws_ssoadmin_permission_set.example.arn
  inline_policy = <<POLICY
{
  "Statement": [
    {
      "Action": [
        "*"
      ],
      "Effect": "Allow",
      "Resource": [
        "*"
      ],
      "Sid": ""
    }
  ],
  "Version": "2012-10-17"
}
POLICY
}

This allows all actions and resources. Review its impact on the accounts, users and groups actually assigned this permission set.

After

hcl
resource "aws_ssoadmin_permission_set_inline_policy" "example" {
  instance_arn       = aws_ssoadmin_permission_set.example.instance_arn
  permission_set_arn = aws_ssoadmin_permission_set.example.arn
  inline_policy = <<POLICY
{
  "Statement": [
    {
      "Action": [
        "s3:ListBucket*",
        "s3:Get*"
      ],
      "Effect": "Allow",
      "Resource": [
        "arn:aws:s3:::example-bucket-one",
        "arn:aws:s3:::example-bucket-one/*",
        "arn:aws:s3:::example-bucket-two",
        "arn:aws:s3:::example-bucket-two/*"
      ],
      "Sid": ""
    }
  ],
  "Version": "2012-10-17"
}
POLICY
}

This limits access to ListBucket* and Get* actions on two buckets. Get* covers multiple retrieval operations; specify actual actions for narrower requirements.

References