IAM user permissions for iam:AttachGroupPolicy need review

Restrict the group-policy changes an IAM user can make.

Description

Overly broad iam:AttachGroupPolicy permissions can let an IAM user attach powerful managed policies to groups and change members’ permissions. If the user can target a group they belong to, their own permissions can also expand.

The targets are IAM groups in the same account. Permission to attach group policies does not itself allow membership changes or administration of other AWS accounts.

Potential impact

  • One user’s incorrect attachment can expand permissions for several group members.
  • Unapproved powerful policies can increase the risk of resource access and modification.

Remediation

Remove unnecessary iam:AttachGroupPolicy permissions and use approved administrative roles. Where needed, specify target group ARNs in Resource and restrict attached policies with iam:PolicyARN conditions. Review membership and other permission limits, and test intended operations and denial of unapproved attachments.

Examples

This comparison keeps the same user and inline policy. A separate policy-attachment resource is not needed for this inline grant.

Before

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "test_inline_policy"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:AttachGroupPolicy",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This permits the user to attach managed policies across groups.

After

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "test_inline_policy"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This replaces that grant with EC2 describe actions. Check whether other policies still grant the same attachment permission.

References