Cloud IAM: Reading a Policy Before You Trust It
Cloud permissions are granted through policies, and the difference between a working policy and a dangerous one is often a single wildcard.
Three things a policy states
Every policy answers three questions: which principal, which action and which resource, optionally constrained by conditions. Reviewing a policy means reading those four elements together rather than scanning for the word *.
The wildcard patterns worth searching for
A wildcard action such as s3:* combined with a wildcard resource grants every operation on every object in the account. An action list that includes iam:PassRole next to a broad compute permission allows a principal to hand an over-privileged role to a service it controls, which is a privilege escalation path rather than a simple permission.
A wildcard principal combined with an allow effect on a data resource is a public grant. That combination appears in storage policies far more often than teams expect.
Controls that limit blast radius
Permissions boundaries cap the maximum permissions an identity policy can grant, so a delegated administrator cannot escalate beyond the boundary. Access Analyzer identifies resources shared with external entities and policies that grant unused permissions.
The IAM Access Advisor data, which records the last time a service was used, turns the least-privilege conversation from a guess into a sequence of concrete removals.
A maintainable process
Treat policy change as a reviewed change. Generate permission sets from observed usage, remove unused grants on a schedule, and alert on the creation of wildcard administrative policies. Centralised root and break-glass identities should be monitored separately from ordinary accounts, because a change there is always meaningful.
References
- AWS documentation, Security best practices in IAM: https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html
- AWS documentation, IAM Access Analyzer: https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html
- Microsoft Learn, Best practices for Azure RBAC: https://learn.microsoft.com/en-us/azure/role-based-access-control/best-practices
Top comments (0)