IAM user permissions for iam:SetDefaultPolicyVersion need review

Restrict which older managed-policy versions a user can activate.

Description

Broad iam:SetDefaultPolicyVersion permissions let an IAM user make an existing customer managed policy version the default. Activating a more permissive version of a policy that applies directly to the user or through a group can increase the user’s permissions.

This action does not let the user write arbitrary new policy contents. Risk depends on the existing versions and affected identities; other applicable restrictions and explicit denies still apply.

Potential impact

  • Previously reduced access can become effective again.
  • Permissions can also change for other users or roles sharing the same policy.

Remediation

Remove unnecessary iam:SetDefaultPolicyVersion from ordinary users and manage versions through approved roles. Restrict Resource to target customer managed policy ARNs and review existing version contents and affected identities. Check iam:CreatePolicyVersion too, and test that approved changes work and unapproved changes are blocked.

Examples

This compares an inline policy on the same user. The inline policy grants permission to change a customer managed policy’s default version.

Before

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "test_inline_policy"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:SetDefaultPolicyVersion",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

The user can select an existing version as default across customer managed policies.

After

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "test_inline_policy"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This statement now contains only EC2 describe actions. Review version-change rights in other policies and the describe scope actually needed.

References