> ## Documentation Index
> Fetch the complete documentation index at: https://cloudanix.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Blocked KMS Actions In Inline Policies Should Be Set

### More Info:

This rule checks if the inline policies attached to your IAM users do not allow blocked actions on all AWS Key Management Service (KMS) keys. The rule is NON\_COMPLIANT if any blocked action is allowed on all AWS KMS keys in an inline policy.

### Risk Level

Medium

### Address

Security

### Compliance Standards

* APRA CPS 234 (Australia)
* BSI C5 (Germany)
* Brazil LGPD
* CCPA / CPRA (California)
* CIS Critical Security Controls v8
* CMMC 2.0
* CSA Cloud Controls Matrix v4
* Cloudanix Best Practice
* DPDPA
* Digital Operational Resilience Act (EU)
* Essential 8
* ISO/IEC 27017
* ISO/IEC 27018
* ISO/IEC 27701
* KSA PDPL
* MAS Technology Risk Management (Singapore)
* MITRE ATT\&CK (Cloud)
* NIS2 Directive
* NIST SP 800-171
* NYDFS 23 NYCRR 500
* SWIFT Customer Security Controls Framework
* Sarbanes-Oxley IT General Controls
* UK NCSC Cyber Assessment Framework

### Triage and Remediation

<Tabs>
  <Tab title="Prevention">
    ### How to Prevent

    <AccordionGroup>
      <Accordion title="Using Console" defaultOpen="true">
        To prevent blocked KMS actions in inline policies in IAM using the AWS Management Console, follow these steps:

        1. **Navigate to IAM Policies:**
           * Open the AWS Management Console.
           * In the navigation pane, choose "Policies" under the "Access management" section.

        2. **Create or Edit a Policy:**
           * To create a new policy, click on the "Create policy" button.
           * To edit an existing policy, find the policy you want to modify and click on its name, then click the "Edit policy" button.

        3. **Specify KMS Actions:**
           * In the policy editor, switch to the "JSON" tab.
           * Ensure that the policy explicitly specifies the allowed KMS actions. For example:
             ```json theme={null}
             {
               "Version": "2012-10-17",
               "Statement": [
                 {
                   "Effect": "Allow",
                   "Action": [
                     "kms:Encrypt",
                     "kms:Decrypt",
                     "kms:GenerateDataKey"
                   ],
                   "Resource": "*"
                 }
               ]
             }
             ```

        4. **Review and Save:**
           * After specifying the allowed KMS actions, click on the "Review policy" button.
           * Provide a name and description for the policy if creating a new one.
           * Click on the "Create policy" or "Save changes" button to apply the policy.

        By following these steps, you ensure that the inline policies in IAM explicitly allow the necessary KMS actions, preventing any misconfigurations related to blocked KMS actions.
      </Accordion>

      <Accordion title="Using CLI">
        To prevent blocked KMS actions in inline policies in IAM using AWS CLI, you can follow these steps:

        1. **Create a JSON Policy Document**:
           * First, create a JSON file that defines the inline policy with the necessary permissions and explicitly denies the blocked KMS actions.
           * Example JSON policy (`policy.json`):
             ```json theme={null}
             {
               "Version": "2012-10-17",
               "Statement": [
                 {
                   "Effect": "Allow",
                   "Action": [
                     "kms:Encrypt",
                     "kms:Decrypt",
                     "kms:GenerateDataKey"
                   ],
                   "Resource": "*"
                 },
                 {
                   "Effect": "Deny",
                   "Action": [
                     "kms:DisableKey",
                     "kms:ScheduleKeyDeletion"
                   ],
                   "Resource": "*"
                 }
               ]
             }
             ```

        2. **Attach the Inline Policy to an IAM User**:
           * Use the `put-user-policy` command to attach the inline policy to a specific IAM user.
           * Command:
             ```sh theme={null}
             aws iam put-user-policy --user-name <username> --policy-name <policy-name> --policy-document file://policy.json
             ```

        3. **Attach the Inline Policy to an IAM Group**:
           * Use the `put-group-policy` command to attach the inline policy to a specific IAM group.
           * Command:
             ```sh theme={null}
             aws iam put-group-policy --group-name <groupname> --policy-name <policy-name> --policy-document file://policy.json
             ```

        4. **Attach the Inline Policy to an IAM Role**:
           * Use the `put-role-policy` command to attach the inline policy to a specific IAM role.
           * Command:
             ```sh theme={null}
             aws iam put-role-policy --role-name <rolename> --policy-name <policy-name> --policy-document file://policy.json
             ```

        By following these steps, you can ensure that the necessary KMS actions are allowed while explicitly denying the blocked KMS actions in inline policies using AWS CLI.
      </Accordion>

      <Accordion title="Using Python">
        To prevent blocked KMS actions in inline policies in IAM using Python scripts, you can use the AWS SDK for Python (Boto3). Here are the steps to achieve this:

        ### Step 1: Install Boto3

        Ensure you have Boto3 installed in your Python environment. You can install it using pip if you haven't already:

        ```bash theme={null}
        pip install boto3
        ```

        ### Step 2: Initialize Boto3 Client

        Initialize the Boto3 client for IAM:

        ```python theme={null}
        import boto3

        iam_client = boto3.client('iam')
        ```

        ### Step 3: Define the Inline Policy

        Create a JSON structure for the inline policy that blocks specific KMS actions. For example, you can block the `kms:Decrypt` action:

        ```python theme={null}
        inline_policy = {
            "Version": "2012-10-17",
            "Statement": [
                {
                    "Effect": "Deny",
                    "Action": [
                        "kms:Decrypt"
                    ],
                    "Resource": "*"
                }
            ]
        }
        ```

        ### Step 4: Attach the Inline Policy to an IAM User or Role

        Attach the inline policy to a specific IAM user or role. Here’s an example of attaching it to a user:

        ```python theme={null}
        user_name = 'your-iam-user-name'
        policy_name = 'BlockKMSActionsPolicy'

        response = iam_client.put_user_policy(
            UserName=user_name,
            PolicyName=policy_name,
            PolicyDocument=json.dumps(inline_policy)
        )

        print(f"Policy {policy_name} attached to user {user_name}")
        ```

        ### Full Script Example

        Here is the complete script combining all the steps:

        ```python theme={null}
        import boto3
        import json

        # Initialize Boto3 client
        iam_client = boto3.client('iam')

        # Define the inline policy
        inline_policy = {
            "Version": "2012-10-17",
            "Statement": [
                {
                    "Effect": "Deny",
                    "Action": [
                        "kms:Decrypt"
                    ],
                    "Resource": "*"
                }
            ]
        }

        # Attach the inline policy to an IAM user
        user_name = 'your-iam-user-name'
        policy_name = 'BlockKMSActionsPolicy'

        response = iam_client.put_user_policy(
            UserName=user_name,
            PolicyName=policy_name,
            PolicyDocument=json.dumps(inline_policy)
        )

        print(f"Policy {policy_name} attached to user {user_name}")
        ```

        ### Summary

        1. **Install Boto3**: Ensure Boto3 is installed in your Python environment.
        2. **Initialize Boto3 Client**: Set up the IAM client using Boto3.
        3. **Define the Inline Policy**: Create a JSON structure for the inline policy to block specific KMS actions.
        4. **Attach the Inline Policy**: Use the `put_user_policy` method to attach the policy to an IAM user.

        By following these steps, you can prevent blocked KMS actions in inline policies using Python scripts.
      </Accordion>
    </AccordionGroup>
  </Tab>

  <Tab title="Cause">
    ### Check Cause

    <AccordionGroup>
      <Accordion title="Using Console" defaultOpen="true">
        1. Sign in to the AWS Management Console and open the IAM console at [https://console.aws.amazon.com/iam/](https://console.aws.amazon.com/iam/).

        2. In the navigation pane, choose "Policies". This will open a list of all the IAM policies that are currently configured in your AWS environment.

        3. Select the policy you want to check for blocked KMS actions. This will open the policy details page.

        4. In the policy details page, check the policy document for any "Deny" statements that are applied to KMS actions. If there are any "Deny" statements applied to KMS actions, then the policy is blocking those actions.
      </Accordion>

      <Accordion title="Using CLI">
        1. First, you need to install and configure AWS CLI on your local machine. You can do this by following the instructions provided by AWS. Make sure you have the necessary permissions to execute IAM related commands.

        2. Once the AWS CLI is set up, you can list all the IAM policies using the following command:
           ```
           aws iam list-policies --scope Local
           ```
           This command will return a list of all the IAM policies that are created within your AWS account.

        3. For each policy, you can get the policy details including the policy document by using the following command:
           ```
           aws iam get-policy-version --policy-arn <Policy_ARN> --version-id <Policy_Version_ID>
           ```
           Replace `<Policy_ARN>` with the ARN of the policy and `<Policy_Version_ID>` with the version ID of the policy. This command will return the policy document which includes the permissions set by the policy.

        4. Now, you need to check the policy document for any blocked KMS actions. You can do this by looking for "kms:Deny" statements in the policy document. If you find any such statements, it means that some KMS actions are blocked in the inline policy. You can use a JSON parser or a script to automate this process. For example, in Python, you can use the `json` module to parse the policy document and check for blocked KMS actions.
      </Accordion>

      <Accordion title="Using Python">
        1. Install and configure AWS SDK for Python (Boto3):
           You need to install and configure Boto3 to interact with AWS services. You can install it using pip:
           ```
           pip install boto3
           ```
           Then, configure your AWS credentials either by setting the following environment variables:
           ```
           AWS_ACCESS_KEY_ID = 'your_access_key'
           AWS_SECRET_ACCESS_KEY = 'your_secret_key'
           ```
           Or, you can create the credential file yourself at \~/.aws/credentials. At a minimum, it should look like this:
           ```
           [default]
           aws_access_key_id = YOUR_ACCESS_KEY
           aws_secret_access_key = YOUR_SECRET_KEY
           ```

        2. Use Boto3 to list all IAM policies:
           You can use the `list_policies` method to retrieve all IAM policies. Here is a sample script:
           ```python theme={null}
           import boto3

           # Create IAM client
           iam = boto3.client('iam')

           # List policies
           response = iam.list_policies(Scope='All')
           for policy in response['Policies']:
               print(policy['PolicyName'])
           ```

        3. Get the policy details:
           For each policy, you can use the `get_policy` method to retrieve the policy details, including the policy document. Here is a sample script:
           ```python theme={null}
           import boto3

           # Create IAM client
           iam = boto3.client('iam')

           # Get policy
           response = iam.get_policy(PolicyArn='arn:aws:iam::aws:policy/AdministratorAccess')
           policy_document = response['Policy']['PolicyDocument']
           print(policy_document)
           ```

        4. Check for blocked KMS actions:
           You can parse the policy document to check if it contains any blocked KMS actions. Here is a sample script:
           ```python theme={null}
           import boto3
           import json

           # Create IAM client
           iam = boto3.client('iam')

           # Get policy
           response = iam.get_policy(PolicyArn='arn:aws:iam::aws:policy/AdministratorAccess')
           policy_document = response['Policy']['PolicyDocument']

           # Parse policy document
           policy_document = json.loads(policy_document)

           # Check for blocked KMS actions
           for statement in policy_document['Statement']:
               if 'kms:Decrypt' in statement['Action'] and statement['Effect'] == 'Deny':
                   print('Blocked KMS action found: kms:Decrypt')
           ```
           This script checks if the 'kms:Decrypt' action is blocked. You can modify it to check for other KMS actions.
      </Accordion>
    </AccordionGroup>
  </Tab>

  <Tab title="Remediation">
    ### Remediation

    <AccordionGroup>
      <Accordion title="Using Console" defaultOpen="true">
        To remediate the issue of blocked KMS actions in inline policies in AWS IAM using the AWS Management Console, follow these step-by-step instructions:

        1. **Sign in to the AWS Management Console**:
           * Navigate to the AWS Management Console ([https://aws.amazon.com/console/](https://aws.amazon.com/console/)) and sign in with your AWS account credentials.

        2. **Access the IAM service**:
           * In the AWS Management Console, search for "IAM" in the services search bar and click on the "IAM" service to access the IAM dashboard.

        3. **Identify the user/group/role with inline policy**:
           * Identify the user, group, or role that has an inline policy with blocked KMS actions. You can do this by navigating to the respective User, Group, or Role within the IAM dashboard.

        4. **Edit the inline policy**:
           * Select the user, group, or role that has the inline policy with blocked KMS actions.
           * Under the "Permissions" tab, locate the inline policy that contains the blocked KMS actions.
           * Click on the inline policy to edit it.

        5. **Update the inline policy**:
           * Within the inline policy editor, locate the section where KMS actions are defined.
           * Remove any explicit deny statements that block KMS actions. Ensure that the necessary KMS actions are allowed as per your organization's policies.

        6. **Save the changes**:
           * After updating the inline policy to allow the required KMS actions, review the changes to ensure they are correct.
           * Click on the "Save changes" or "Update policy" button to save the modified inline policy.

        7. **Verify the changes**:
           * Once the inline policy is updated, verify that the blocked KMS actions have been remediated.
           * You can test the permissions by attempting to perform the KMS actions that were previously blocked.

        8. **Monitor for compliance**:
           * Regularly monitor your IAM policies and permissions to ensure that they comply with your organization's security and compliance requirements.
           * Consider implementing AWS Config rules or AWS CloudTrail logs to track and alert on any future misconfigurations related to KMS actions.

        By following these steps, you can successfully remediate the issue of blocked KMS actions in inline policies within AWS IAM using the AWS Management Console.

        #
      </Accordion>

      <Accordion title="Using CLI">
        To remediate the misconfiguration of blocked KMS actions in inline policies in AWS IAM using AWS CLI, follow these steps:

        Step 1: Identify the IAM user or role with the inline policy containing blocked KMS actions.

        Step 2: Use the AWS CLI to view the inline policy attached to the IAM user or role. Replace `IAM-ENTITY-NAME` with the actual IAM user or role name.

        ```bash theme={null}
        aws iam list-user-policies --user-name IAM-ENTITY-NAME
        ```

        or

        ```bash theme={null}
        aws iam list-role-policies --role-name IAM-ENTITY-NAME
        ```

        Step 3: Get the policy document for the inline policy. Replace `IAM-ENTITY-NAME` with the actual IAM user or role name and `POLICY-NAME` with the policy name.

        ```bash theme={null}
        aws iam get-user-policy --user-name IAM-ENTITY-NAME --policy-name POLICY-NAME
        ```

        or

        ```bash theme={null}
        aws iam get-role-policy --role-name IAM-ENTITY-NAME --policy-name POLICY-NAME
        ```

        Step 4: Review the policy document to identify the blocked KMS actions.

        Step 5: Modify the policy document to allow the required KMS actions. You can create a new policy or update the existing policy based on your requirements.

        Step 6: Update the inline policy for the IAM user or role with the modified policy document. Replace `IAM-ENTITY-NAME`, `POLICY-NAME`, and `POLICY-DOCUMENT` with the actual values.

        ```bash theme={null}
        aws iam put-user-policy --user-name IAM-ENTITY-NAME --policy-name POLICY-NAME --policy-document file://POLICY-DOCUMENT.json
        ```

        or

        ```bash theme={null}
        aws iam put-role-policy --role-name IAM-ENTITY-NAME --policy-name POLICY-NAME --policy-document file://POLICY-DOCUMENT.json
        ```

        Step 7: Verify that the inline policy has been updated successfully by checking the policy document.

        By following these steps, you can remediate the misconfiguration of blocked KMS actions in inline policies in AWS IAM using AWS CLI.
      </Accordion>

      <Accordion title="Using Python">
        To remediate the issue of blocked KMS actions in inline policies for AWS IAM using Python, you can follow these steps:

        1. Identify the IAM user or role with the inline policy that contains blocked KMS actions.
        2. Update the inline policy to allow the necessary KMS actions.
        3. Use the AWS SDK for Python (Boto3) to programmatically update the inline policy.

        Here is a sample Python script to remediate this issue:

        ```python theme={null}
        import boto3

        iam = boto3.client('iam')

        # IAM user or role name with the inline policy containing blocked KMS actions
        entity_name = 'YOUR_IAM_ENTITY_NAME'
        policy_name = 'YOUR_POLICY_NAME'

        # Define the necessary KMS actions to be allowed in the policy
        kms_actions = [
            "kms:Encrypt",
            "kms:Decrypt",
            # Add more KMS actions as needed
        ]

        # Get the current policy document
        response = iam.get_user_policy(UserName=entity_name, PolicyName=policy_name)
        policy_document = response['PolicyDocument']

        # Update the policy document to allow the KMS actions
        for statement in policy_document['Statement']:
            if 'Resource' in statement and statement['Resource'].startswith('arn:aws:kms'):
                if 'Effect' in statement and statement['Effect'] == 'Deny':
                    statement['Effect'] = 'Allow'
                    statement['Action'] = kms_actions

        # Update the policy with the modified document
        iam.put_user_policy(UserName=entity_name, PolicyName=policy_name, PolicyDocument=policy_document)

        print(f"Updated inline policy {policy_name} for {entity_name} to allow KMS actions: {kms_actions}")
        ```

        Make sure to replace `YOUR_IAM_ENTITY_NAME` and `YOUR_POLICY_NAME` with the appropriate values for your IAM user or role and policy name.

        After running this script, the inline policy for the specified IAM user or role should be updated to allow the necessary KMS actions, remedying the misconfiguration.
      </Accordion>

      <Accordion title="Using Terraform">
        ```hcl theme={null}
        resource "aws_iam_user" "example" {
          name = "EXISTING_USER_NAME" # replace with your IAM user name
        }

        resource "aws_iam_user_policy" "kms_restricted" {
          name = "EXISTING_INLINE_POLICY_NAME" # replace with the inline policy name on the user
          user = aws_iam_user.example.name

          # Replace the JSON below with your existing policy document,
          # but ensure any KMS statements do NOT use "Resource": "*"
          policy = jsonencode({
            Version = "2012-10-17"
            Statement = [
              # Example of a previously over‑permissive statement:
              # {
              #   "Effect": "Allow",
              #   "Action": [
              #     "kms:Encrypt",
              #     "kms:Decrypt",
              #     "kms:GenerateDataKey*"
              #   ],
              #   "Resource": "*"
              # }

              # Corrected: restrict KMS actions to specific key ARNs (NO "*")
              {
                Effect = "Allow"
                Action = [
                  "kms:Encrypt",
                  "kms:Decrypt",
                  "kms:GenerateDataKey*",
                ]
                Resource = [
                  "arn:aws:kms:AWS_REGION:AWS_ACCOUNT_ID:key/KMS_KEY_ID_1",
                  "arn:aws:kms:AWS_REGION:AWS_ACCOUNT_ID:key/KMS_KEY_ID_2",
                ]
              }

              # …include any other non‑KMS statements from your existing policy unchanged…
            ]
          })
        }
        ```

        This change updates the inline user policy in place (no resource replacement, but permissions may change and affect workloads).

        For verification, `terraform plan` should show an in-place `update` of `aws_iam_user_policy.kms_restricted` where only the `policy` JSON changes from `Resource: "*"` to the specific KMS key ARNs.
      </Accordion>
    </AccordionGroup>
  </Tab>
</Tabs>

### Additional Reading:

* [https://docs.aws.amazon.com/config/latest/developerguide/iam-inline-policy-blocked-kms-actions.html](https://docs.aws.amazon.com/config/latest/developerguide/iam-inline-policy-blocked-kms-actions.html)
