Updated on 2024-10-15 GMT+08:00

Each User Group Has at Least One User

Rule Details

Table 1 Rule details

Parameter

Description

Rule Name

iam-group-has-users-check

Identifier

iam-group-has-users-check

Description

If an IAM user group has no users, this user group is noncompliant.

Tag

iam

Trigger Type

Configuration change

Filter Type

iam.groups

Configure Rule Parameters

None

Applicable Scenario

Users inherit permissions from their user groups. Adding or removing users from a user group allows you to efficiently manage user permissions. This rule allows you to detect user groups that do not have any users.

Solution

The administrator can assign permissions to user groups and add users to these groups. For more details, see Adding Users to or Removing Users from a User Group

Rule Logic

  • If an IAM user group has no users, this user group is noncompliant.
  • If an IAM user group has one or more users, this user group is compliant.