IAM user permissions for iam:PutUserPolicy need review

Restrict a user’s ability to change their own or other users’ inline policies.

Description

Broad iam:PutUserPolicy permissions let an IAM user add or replace inline policies on themselves or other users. Granting stronger permissions to a target user can enable privilege escalation where other limits do not block the resulting access.

Policy changes do not automatically remove permissions boundaries, organization policies or explicit denies. Review the actual users and other policies together.

Potential impact

  • Users can increase their own resource access or modification rights without approval.
  • Excessive grants to other users can increase the impact of credential misuse.

Remediation

Remove unnecessary iam:PutUserPolicy from ordinary users and perform administration through approved roles. Where needed, restrict Resource to target user ARNs. Review self-modification paths and change logs, and verify that intended work succeeds and unapproved changes are blocked.

Examples

This comparison changes only the allowed actions in the same user and inline policy.

Before

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "test_inline_policy"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:PutUserPolicy",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This grants the user permission to add or update inline policies across users, including themselves.

After

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "test_inline_policy"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This statement now contains only EC2 describe actions. Also review user-policy modification permissions and unnecessary describe access in other policies.

References