Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add SCP to Prevent Creation of New IAM Users or Access Keys #42

Open
sprkyco opened this issue Jun 10, 2021 · 0 comments
Open

Add SCP to Prevent Creation of New IAM Users or Access Keys #42

sprkyco opened this issue Jun 10, 2021 · 0 comments

Comments

@sprkyco
Copy link

sprkyco commented Jun 10, 2021

Use Case - Is your feature request related to a problem? Please describe.
Restrict creation of any new IAM users access keys to prohibit bypass of SSO and other controls

Expected Outcome - Describe the solution you'd like
An SCP which restricts IAM accesskey and user creation explicitly

Describe alternatives you've considered
This may be beneficial to combine with preventing other sensitive IAM actions, but is worthwhile to have this separately to control just access key and new user creation.

Affected AWS resource
IAM

Impact
Low: Niche use case which is particularly affecting the AWS resources if it is configured in a certain way

Supported material
N/A

I can contribute: Yes/No
Yes

Additional context
N/A

Pull Request number
#43

sprkyco pushed a commit to sprkyco/aws-iam-permissions-guardrails that referenced this issue Jun 10, 2021
@sprkyco sprkyco changed the title SCP to Prevent Creation of New IAM Users or Access Keys Add SCP to Prevent Creation of New IAM Users or Access Keys Jun 10, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant