Ensure IAM Group has no inline policy

Security & Compliance

IAM Group inline policies can give unnecessary permissions to the users within the group, which can result in security risks. To prevent this, it is recommended to ensure that IAM groups have no inline policies attached.


To ensure IAM group has no inline policies, follow the below steps:

  1. Open the AWS Management Console and navigate to the IAM dashboard.
  2. In the left navigation pane, select "Groups."
  3. Select the group for which you want to check for inline policies.
  4. In the group summary page, click on the "Permissions" tab.
  5. Review the policies that are listed under "Attached Policies" section. Policies that have the "type" column as "Managed" are managed policies and those with "type" column as "Inline" are inline policies. Remove any inline policies that are not needed by clicking on the "X" icon on the right side of the policy.
  6. Once all inline policies are removed, click on the "Save Changes" button to update the group permissions.

By ensuring IAM groups have no inline policies, you can reduce the risk of granting unnecessary permissions and make it easier to manage group permissions.

