Customer IAM roles with the AWS managed AdministratorAccess policy attached
What does ZopNight detect here?
ZopNight flags a customer-owned IAM role that has `arn:aws:iam::aws:policy/AdministratorAccess` attached, a policy that allows every action on every resource. Service-linked roles, IAM Identity Center roles and Control Tower, Quick Setup and StackSets execution roles are skipped because AWS gives them admin by design. The finding carries a $0 saving.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-081 |
| Category | compliance |
| Severity | high |
| Metric | none — pure configuration read |
| Threshold | AdministratorAccess attached |
| Source | ZopNight |
| Permissions used | iam:ListRoles · iam:ListAttachedRolePolicies · iam:ListEntitiesForPolicy |
Where it applies
What AdministratorAccess actually grants
The AWS managed policy
AdministratorAccess
is a single statement: "Effect": "Allow", "Action": "*", "Resource": "*". Any principal that can
assume a role carrying it can create users, delete backups, read every secret and switch off
logging.
That makes the role’s trust policy the only boundary left. If a CI job, an EC2 instance profile or a third-party integration assumes an admin role, compromising that one component compromises the whole account.
Listing roles that carry the policy
One call returns every role with the policy attached:
aws iam list-entities-for-policy \ --policy-arn arn:aws:iam::aws:policy/AdministratorAccess \ --entity-filter Role --query 'PolicyRoles[].RoleName' --output textFor a single role, check what is attached and who can assume it:
aws iam list-attached-role-policies --role-name my-roleaws iam get-role --role-name my-role --query 'Role.AssumeRolePolicyDocument'How ZopNight decides a role is over-privileged
During discovery ZopNight lists each role’s attached managed policies and records whether the AWS
managed AdministratorAccess ARN is among them. The rule fires when that record says yes. If the
lookup fails for a role, nothing is recorded and no finding is produced. As a fallback, a tag
has_admin_access=true that you apply yourself is also honoured.
Roles AWS gives admin on purpose
Some roles need full access for an AWS service to work, and detaching the policy would break that service. ZopNight never flags:
- roles under the
/aws-service-role/path, which are service-linked roles; - roles under
/aws-reserved/, which is where IAM Identity Center places itsAWSReservedSSO_roles; - roles whose names start with
AWSControlTower,aws-controltower-,AWS-QuickSetup-,AWSReservedSSO_orstacksets-exec-.
The check also reads only the AWS managed policy. A customer-managed or inline policy that grants
* on * is not detected here.
The risk this finding measures
No money is saved by fixing it. The value is blast radius: an admin role turns any compromise of whatever assumes it into a full account compromise.
Replacing admin with least privilege
- Find what the role really does. IAM Access Analyzer policy generation builds a policy from the role’s CloudTrail activity.
- Attach the generated or a scoped AWS managed policy alongside AdministratorAccess.
- Detach the admin policy:
aws iam detach-role-policy --role-name my-role \ --policy-arn arn:aws:iam::aws:policy/AdministratorAccess- Watch the workload’s logs for
AccessDeniederrors for a few days and add missing actions.