IAM user permissions for iam:AddUserToGroup need review

Restrict which IAM groups a user can add themselves or other users to.

Description

Broad iam:AddUserToGroup permissions let an IAM user add themselves or other IAM users to groups in the same account. If the target group grants greater effective permissions, this can enable privilege escalation for the caller or another user they control.

Resource specifies the target group ARN, not the ARN of the user being added. Review both the user and the destination group. Permissions boundaries, organization policies and explicit denies can still limit the permissions granted.

Potential impact

  • A user can gain the access granted by a privileged group without approval.
  • Unnecessary permissions granted to another user can expand access to sensitive resources.

Remediation

Remove unnecessary iam:AddUserToGroup from ordinary users and make membership changes through approved administration roles. Restrict Resource to required target group ARNs and approve the users to add through the change process. Test that required changes work and unapproved additions are blocked, and review change logs.

Examples

This comparison removes group-membership modification permission while retaining the same user and inline policy.

Before

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "test_inline_policy"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:AddUserToGroup",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This grants the user permission to add users to groups throughout the account.

After

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "test_inline_policy"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This statement now contains only EC2 describe actions. Review group-membership rights granted through other policies and the describe scope.

References