AWS IAM policy best practices: least privilege without the pain
How to write secure AWS IAM policies: least privilege, roles instead of access keys, permission boundaries, SCPs, conditions and IAM Access Analyzer.
How to write secure AWS IAM policies: least privilege, roles instead of access keys, permission boundaries, SCPs, conditions and IAM Access Analyzer.
How IAM policies are evaluated
An IAM request is allowed only if an identity or resource policy explicitly allows it and nothing explicitly denies it. Explicit deny always wins. Service control policies (SCPs) and permission boundaries set the maximum permissions — they never grant access on their own.
RELATED GUIDE12 proven ways to reduce your AWS bill →1. Prefer roles and short-lived credentials
Give people access through IAM Identity Center (single sign-on) and give workloads IAM roles (EC2 instance profiles, ECS task roles, Lambda execution roles). Temporary credentials expire automatically, so leaked keys are far less dangerous.
2. Apply least privilege
- Start with AWS managed job-function policies, then narrow down
- Use IAM Access Analyzer to generate policies from CloudTrail activity
- Scope Resource to specific ARNs instead of “*”
- Review “last accessed” data and remove unused permissions
3. Use conditions
Conditions make policies much safer. Common examples: require MFA (aws:MultiFactorAuthPresent), restrict by source VPC or IP (aws:SourceVpc, aws:SourceIp), enforce tags (aws:ResourceTag) and limit regions (aws:RequestedRegion).
4. Guardrails with SCPs and permission boundaries
In AWS Organizations, SCPs stop anyone — even administrators — from doing things like disabling CloudTrail, leaving the organisation or using unapproved regions. Permission boundaries let developers create roles without being able to escalate their own privileges.
5. Monitor and audit
- Enable CloudTrail in every account and region
- Turn on IAM Access Analyzer for external and unused access
- Use AWS Config rules and Security Hub for IAM checks
- Manage IAM in Terraform so every change is reviewed
Common mistakes to avoid
How we help with cloud
Frequently asked questions
What is least privilege in AWS?
Granting only the permissions needed for a task, on only the resources needed, for only as long as needed.
Should I use IAM users?
For people, AWS recommends IAM Identity Center instead of IAM users. For workloads, use roles.
What is the difference between an SCP and an IAM policy?
An SCP sets the maximum permissions for accounts in an organisation; IAM policies grant permissions within that limit.