Skip to main content
compliance · aws

Customer IAM roles with the AWS managed AdministratorAccess policy attached

resource types
1
rule IDs covered
1
severity
high

What does ZopNight detect here?

ZopNight flags a customer-owned IAM role that has `arn:aws:iam::aws:policy/AdministratorAccess` attached, a policy that allows every action on every resource. Service-linked roles, IAM Identity Center roles and Control Tower, Quick Setup and StackSets execution roles are skipped because AWS gives them admin by design. The finding carries a $0 saving.

Signal and threshold

How ZopNight evaluates Customer IAM roles with the AWS managed AdministratorAccess policy attached.
Field Value
Rule IDsRC-081
Categorycompliance
Severityhigh
Metricnone — pure configuration read
ThresholdAdministratorAccess attached
SourceZopNight
Permissions usediam:ListRoles · iam:ListAttachedRolePolicies · iam:ListEntitiesForPolicy

What AdministratorAccess actually grants

The AWS managed policy AdministratorAccess is a single statement: "Effect": "Allow", "Action": "*", "Resource": "*". Any principal that can assume a role carrying it can create users, delete backups, read every secret and switch off logging.

That makes the role’s trust policy the only boundary left. If a CI job, an EC2 instance profile or a third-party integration assumes an admin role, compromising that one component compromises the whole account.

Listing roles that carry the policy

One call returns every role with the policy attached:

Terminal window
aws iam list-entities-for-policy \
--policy-arn arn:aws:iam::aws:policy/AdministratorAccess \
--entity-filter Role --query 'PolicyRoles[].RoleName' --output text

For a single role, check what is attached and who can assume it:

Terminal window
aws iam list-attached-role-policies --role-name my-role
aws iam get-role --role-name my-role --query 'Role.AssumeRolePolicyDocument'

How ZopNight decides a role is over-privileged

During discovery ZopNight lists each role’s attached managed policies and records whether the AWS managed AdministratorAccess ARN is among them. The rule fires when that record says yes. If the lookup fails for a role, nothing is recorded and no finding is produced. As a fallback, a tag has_admin_access=true that you apply yourself is also honoured.

Roles AWS gives admin on purpose

Some roles need full access for an AWS service to work, and detaching the policy would break that service. ZopNight never flags:

The check also reads only the AWS managed policy. A customer-managed or inline policy that grants * on * is not detected here.

The risk this finding measures

No money is saved by fixing it. The value is blast radius: an admin role turns any compromise of whatever assumes it into a full account compromise.

Replacing admin with least privilege

  1. Find what the role really does. IAM Access Analyzer policy generation builds a policy from the role’s CloudTrail activity.
  2. Attach the generated or a scoped AWS managed policy alongside AdministratorAccess.
  3. Detach the admin policy:
Terminal window
aws iam detach-role-policy --role-name my-role \
--policy-arn arn:aws:iam::aws:policy/AdministratorAccess
  1. Watch the workload’s logs for AccessDenied errors for a few days and add missing actions.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·