IAM Users Policy Blacklisted Check Remediation
Triage and Remediation
- Prevention
- Cause
- Remediation
How to Prevent
Using Console
To prevent blocked KMS actions in inline policies in IAM using the AWS Management Console, follow these steps:
-
Navigate to IAM Policies:
- Open the AWS Management Console.
- In the navigation pane, choose "Policies" under the "Access management" section.
-
Create or Edit a Policy:
- To create a new policy, click on the "Create policy" button.
- To edit an existing policy, find the policy you want to modify and click on its name, then click the "Edit policy" button.
-
Specify KMS Actions:
- In the policy editor, switch to the "JSON" tab.
- Ensure that the policy explicitly specifies the allowed KMS actions. For example:
{"Version": "2012-10-17","Statement": [{"Effect": "Allow","Action": ["kms:Encrypt","kms:Decrypt","kms:GenerateDataKey"],"Resource": "*"}]}
-
Review and Save:
- After specifying the allowed KMS actions, click on the "Review policy" button.
- Provide a name and description for the policy if creating a new one.
- Click on the "Create policy" or "Save changes" button to apply the policy.
By following these steps, you ensure that the inline policies in IAM explicitly allow the necessary KMS actions, preventing any misconfigurations related to blocked KMS actions.
Using CLI
To prevent blocked KMS actions in inline policies in IAM using AWS CLI, you can follow these steps:
-
Create a JSON Policy Document:
- First, create a JSON file that defines the inline policy with the necessary permissions and explicitly denies the blocked KMS actions.
- Example JSON policy (
policy.json):{"Version": "2012-10-17","Statement": [{"Effect": "Allow","Action": ["kms:Encrypt","kms:Decrypt","kms:GenerateDataKey"],"Resource": "*"},{"Effect": "Deny","Action": ["kms:DisableKey","kms:ScheduleKeyDeletion"],"Resource": "*"}]}
-
Attach the Inline Policy to an IAM User:
- Use the
put-user-policycommand to attach the inline policy to a specific IAM user. - Command:
aws iam put-user-policy --user-name <username> --policy-name <policy-name> --policy-document file://policy.json
- Use the
-
Attach the Inline Policy to an IAM Group:
- Use the
put-group-policycommand to attach the inline policy to a specific IAM group. - Command:
aws iam put-group-policy --group-name <groupname> --policy-name <policy-name> --policy-document file://policy.json
- Use the
-
Attach the Inline Policy to an IAM Role:
- Use the
put-role-policycommand to attach the inline policy to a specific IAM role. - Command:
aws iam put-role-policy --role-name <rolename> --policy-name <policy-name> --policy-document file://policy.json
- Use the
By following these steps, you can ensure that the necessary KMS actions are allowed while explicitly denying the blocked KMS actions in inline policies using AWS CLI.
Using Python
To prevent blocked KMS actions in inline policies in IAM using Python scripts, you can use the AWS SDK for Python (Boto3). Here are the steps to achieve this:
Step 1: Install Boto3
Ensure you have Boto3 installed in your Python environment. You can install it using pip if you haven't already:
pip install boto3
Step 2: Initialize Boto3 Client
Initialize the Boto3 client for IAM:
import boto3
iam_client = boto3.client('iam')
Step 3: Define the Inline Policy
Create a JSON structure for the inline policy that blocks specific KMS actions. For example, you can block the kms:Decrypt action:
inline_policy = {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Deny",
"Action": [
"kms:Decrypt"
],
"Resource": "*"
}
]
}
Step 4: Attach the Inline Policy to an IAM User or Role
Attach the inline policy to a specific IAM user or role. Here’s an example of attaching it to a user:
user_name = 'your-iam-user-name'
policy_name = 'BlockKMSActionsPolicy'
response = iam_client.put_user_policy(
UserName=user_name,
PolicyName=policy_name,
PolicyDocument=json.dumps(inline_policy)
)
print(f"Policy {policy_name} attached to user {user_name}")
Full Script Example
Here is the complete script combining all the steps:
import boto3
import json
# Initialize Boto3 client
iam_client = boto3.client('iam')
# Define the inline policy
inline_policy = {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Deny",
"Action": [
"kms:Decrypt"
],
"Resource": "*"
}
]
}
# Attach the inline policy to an IAM user
user_name = 'your-iam-user-name'
policy_name = 'BlockKMSActionsPolicy'
response = iam_client.put_user_policy(
UserName=user_name,
PolicyName=policy_name,
PolicyDocument=json.dumps(inline_policy)
)
print(f"Policy {policy_name} attached to user {user_name}")
Summary
- Install Boto3: Ensure Boto3 is installed in your Python environment.
- Initialize Boto3 Client: Set up the IAM client using Boto3.
- Define the Inline Policy: Create a JSON structure for the inline policy to block specific KMS actions.
- Attach the Inline Policy: Use the
put_user_policymethod to attach the policy to an IAM user.
By following these steps, you can prevent blocked KMS actions in inline policies using Python scripts.
Check Cause
Using Console
-
Sign in to the AWS Management Console and open the IAM console at https://console.aws.amazon.com/iam/.
-
In the navigation pane, choose "Policies". This will open a list of all the IAM policies that are currently configured in your AWS environment.
-
Select the policy you want to check for blocked KMS actions. This will open the policy details page.
-
In the policy details page, check the policy document for any "Deny" statements that are applied to KMS actions. If there are any "Deny" statements applied to KMS actions, then the policy is blocking those actions.
Using CLI
-
First, you need to install and configure AWS CLI on your local machine. You can do this by following the instructions provided by AWS. Make sure you have the necessary permissions to execute IAM related commands.
-
Once the AWS CLI is set up, you can list all the IAM policies using the following command:
aws iam list-policies --scope LocalThis command will return a list of all the IAM policies that are created within your AWS account.
-
For each policy, you can get the policy details including the policy document by using the following command:
aws iam get-policy-version --policy-arn <Policy_ARN> --version-id <Policy_Version_ID>Replace
<Policy_ARN>with the ARN of the policy and<Policy_Version_ID>with the version ID of the policy. This command will return the policy document which includes the permissions set by the policy. -
Now, you need to check the policy document for any blocked KMS actions. You can do this by looking for "kms:Deny" statements in the policy document. If you find any such statements, it means that some KMS actions are blocked in the inline policy. You can use a JSON parser or a script to automate this process. For example, in Python, you can use the
jsonmodule to parse the policy document and check for blocked KMS actions.
Using Python
-
Install and configure AWS SDK for Python (Boto3): You need to install and configure Boto3 to interact with AWS services. You can install it using pip:
pip install boto3Then, configure your AWS credentials either by setting the following environment variables:
AWS_ACCESS_KEY_ID = 'your_access_key'AWS_SECRET_ACCESS_KEY = 'your_secret_key'Or, you can create the credential file yourself at ~/.aws/credentials. At a minimum, it should look like this:
[default]aws_access_key_id = YOUR_ACCESS_KEYaws_secret_access_key = YOUR_SECRET_KEY -
Use Boto3 to list all IAM policies: You can use the
list_policiesmethod to retrieve all IAM policies. Here is a sample script:import boto3# Create IAM clientiam = boto3.client('iam')# List policiesresponse = iam.list_policies(Scope='All')for policy in response['Policies']:print(policy['PolicyName']) -
Get the policy details: For each policy, you can use the
get_policymethod to retrieve the policy details, including the policy document. Here is a sample script:import boto3# Create IAM clientiam = boto3.client('iam')# Get policyresponse = iam.get_policy(PolicyArn='arn:aws:iam::aws:policy/AdministratorAccess')policy_document = response['Policy']['PolicyDocument']print(policy_document) -
Check for blocked KMS actions: You can parse the policy document to check if it contains any blocked KMS actions. Here is a sample script:
import boto3import json# Create IAM clientiam = boto3.client('iam')# Get policyresponse = iam.get_policy(PolicyArn='arn:aws:iam::aws:policy/AdministratorAccess')policy_document = response['Policy']['PolicyDocument']# Parse policy documentpolicy_document = json.loads(policy_document)# Check for blocked KMS actionsfor statement in policy_document['Statement']:if 'kms:Decrypt' in statement['Action'] and statement['Effect'] == 'Deny':print('Blocked KMS action found: kms:Decrypt')This script checks if the 'kms:Decrypt' action is blocked. You can modify it to check for other KMS actions.
Remediation
Using Console
To remediate the issue of blocked KMS actions in inline policies in AWS IAM using the AWS Management Console, follow these step-by-step instructions:
-
Identify the Inline Policies:
- Sign in to the AWS Management Console.
- Open the IAM console at https://console.aws.amazon.com/iam/.
- In the navigation pane, choose "Policies".
- Select the policy that contains the inline policy with blocked KMS actions.
-
Edit the Inline Policy:
- Click on the policy name to open the policy details.
- In the "Policy summary" section, find the inline policy that contains the blocked KMS actions.
- Click on the "Edit policy" button to modify the inline policy.
-
Update the Policy Document:
- In the policy editor, locate the section that specifies the actions allowed or denied.
- Remove any explicit denies for KMS actions that are necessary for your use case.
- Ensure that the policy allows the required KMS actions by using the appropriate IAM policy actions (e.g., kms:Encrypt, kms:Decrypt, kms:GenerateDataKey, etc.).
-
Review and Save the Changes:
- After updating the policy document to allow the necessary KMS actions, review the changes to ensure they meet your security and access requirements.
- Click on the "Review policy" button to validate the policy syntax.
- Once the policy syntax is valid, click on the "Save changes" button to update the inline policy.
-
Test the Policy:
- After saving the changes, test the inline policy to ensure that the required KMS actions are now allowed.
- You can test the policy by assigning it to a user or role and performing the relevant actions that involve KMS encryption/decryption.
By following these steps, you can remediate the issue of blocked KMS actions in inline policies in AWS IAM using the AWS Management Console. It is essential to regularly review and update IAM policies to ensure that they align with your organization's security and compliance requirements.
Using CLI
To remediate the issue of blocked KMS actions in inline policies in AWS IAM using AWS CLI, follow these steps:
-
Identify the IAM user or role with inline policies that contain blocked KMS actions.
-
Open your terminal and execute the following AWS CLI command to list all IAM users and roles with inline policies that contain blocked KMS actions:
aws iam list-entities-for-policy --policy-arn arn:aws:iam::aws:policy/AWSKeyManagementServicePowerUserPolicy -
Identify the inline policy attached to the IAM user or role that contains blocked KMS actions.
-
Modify the inline policy to allow the necessary KMS actions. You can do this by creating a new inline policy with the required KMS permissions and attaching it to the IAM user or role.
-
Use the AWS CLI command to create a new inline policy with the required KMS permissions. Save the policy document in a JSON file (e.g., kms_policy.json) with the necessary permissions. Here is an example of a policy document that allows all KMS actions:
{"Version": "2012-10-17","Statement": [{"Effect": "Allow","Action": "kms:*","Resource": "*"}]} -
Execute the following AWS CLI command to attach the new inline policy to the IAM user or role:
aws iam put-user-policy --user-name <IAM-USER-NAME> --policy-name AllowKMSActions --policy-document file://kms_policy.json -
Verify that the new inline policy with the required KMS permissions has been successfully attached to the IAM user or role by listing the user policies:
aws iam list-user-policies --user-name <IAM-USER-NAME> -
Test the IAM user or role to ensure that they can now perform the necessary KMS actions without any issues.
By following these steps, you can remediate the issue of blocked KMS actions in inline policies in AWS IAM using AWS CLI.
Using Python
To remediate the issue of blocked KMS actions in inline policies in AWS IAM using Python, you can follow these steps:
- Identify the IAM user or role with the inline policy that is blocking KMS actions.
- Update the inline policy to allow the necessary KMS actions.
Here is an example Python script that demonstrates how to remediate this issue:
import boto3
# Initialize the IAM client
iam_client = boto3.client('iam')
# Specify the IAM user or role name with the inline policy blocking KMS actions
user_or_role_name = 'YOUR_USER_OR_ROLE_NAME'
# Specify the KMS actions that need to be allowed
kms_actions = ['kms:Encrypt', 'kms:Decrypt', 'kms:GenerateDataKey']
# Get the inline policies attached to the IAM user or role
response = iam_client.list_user_policies(UserName=user_or_role_name)
policy_names = response['PolicyNames']
# Update each inline policy to allow the necessary KMS actions
for policy_name in policy_names:
policy_document = iam_client.get_user_policy(UserName=user_or_role_name, PolicyName=policy_name)['PolicyDocument']
for statement in policy_document['Statement']:
if statement['Effect'] == 'Deny' and 'kms' in statement['Action']:
for action in kms_actions:
statement['Action'].remove(action)
# Update the policy with the modified document
iam_client.put_user_policy(UserName=user_or_role_name, PolicyName=policy_name, PolicyDocument=policy_document)
print(f"KMS actions have been allowed in the inline policies for {user_or_role_name}")
Make sure to replace 'YOUR_USER_OR_ROLE_NAME' with the actual IAM user or role name that has the inline policy blocking KMS actions. Also, update the kms_actions list with the specific KMS actions that need to be allowed.
By running this Python script, you will be able to remediate the issue of blocked KMS actions in inline policies for the specified IAM user or role in AWS IAM.
Using Terraform
# IAM user remains; the blacklisted policy is NO LONGER attached via Terraform.
resource "aws_iam_user" "example" {
name = "IAM_USER_NAME" # replace with the IAM user name
}
# Example of an allowed policy that may remain attached
resource "aws_iam_user_policy_attachment" "allowed_policy_attachment" {
user = aws_iam_user.example.name
policy_arn = "ALLOWED_POLICY_ARN" # replace with a non‑blacklisted managed policy ARN
}
To remediate, remove (or never create) any aws_iam_user_policy_attachment whose policy_arn equals the blacklisted ARN (the one from ViolatingPolicyArn in the finding). This detaches the blacklisted managed policy from the IAM user and removes all permissions it granted; verify this will not break required workflows.
This change does not replace the IAM user, but it does destroy the attachment. terraform plan should show a - (destroy) for the specific aws_iam_user_policy_attachment resource that referenced the blacklisted policy ARN, and no other unexpected changes.