IAM user permissions for iam:PutGroupPolicy need review

Limit a user’s group inline-policy modifications to approved targets.

Description

Broad iam:PutGroupPolicy permissions let an IAM user add or replace group inline policies and expand members’ permissions. If the user belongs to a target group, they can also use this to escalate their own privileges.

Group policies apply to the IAM users in that group. They do not automatically bypass permissions boundaries, organization policies or explicit denies.

Potential impact

  • Several users can gain access outside the approved group permission process.
  • Misuse of group members’ credentials can have a greater impact.

Remediation

Remove unnecessary iam:PutGroupPolicy from ordinary users. Perform required work through approved administration roles and restrict Resource to target group ARNs. Review policy contents and membership, monitor changes, and verify that intended work succeeds and unapproved changes are blocked.

Examples

This changes allowed actions in the same user and inline policy. A separate managed-policy attachment resource is not needed for this comparison.

Before

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "test_inline_policy"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:PutGroupPolicy",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This grants the user permission to add or update inline policies across groups.

After

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "test_inline_policy"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This statement now contains only EC2 describe actions. Check for group-modification rights through other policies and review the describe access actually needed.

References