Help Center/ Config/ User Guide/ Resource Compliance/ Built-In Policies/ Identity and Access Management/ IAM Users Do Not Have Directly Assigned Policies or Permissions
Updated on 2024-12-10 GMT+08:00

IAM Users Do Not Have Directly Assigned Policies or Permissions

Rule Details

Table 1 Rule details

Parameter

Description

Rule Name

iam-user-no-policies-check

Identifier

iam-user-no-policies-check

Description

If an IAM user has any directly assigned policies or permissions, the IAM user is noncompliant.

Tag

iam

Trigger Type

Configuration change

Filter Type

iam.users

Configure Rule Parameters

None

Applicable Scenario

To assign IAM users permissions, you are advised to add users to a user group and assign permissions to the user group. This makes it easier to manage permissions and helps prevent excessive authorization. For more details, see Assigning Permissions to an IAM User.

Solution

You can remove the policies or permissions from noncompliant IAM users and then, create a user group, add the users to the user group, and add the policies or permissions to the user group.

Rule Logic

  • If an IAM user has any directly assigned policies or permissions, the IAM user is noncompliant.
  • If an IAM user does not have directly assigned policies or permissions, the IAM user is compliant.