Q: How do you enforce least-privilege IAM across enterprise AWS environments?
Enterprise AWS IAM security architecture: replacing static credentials with OIDC role assumption, scoping resource ARNs, enforcing IAM Permission Boundaries to prevent privilege escalation, Service Control Policies (SCPs), and auditing via Access Analyzer.
#AWS #IAM #Security #Permission Boundaries #SCP #Access Analyzer #OIDC
🎙️ Candidate Opening & Architectural Context
"Least privilege means granting only the minimum necessary actions on specific resource ARNs with strict condition keys, and completely eliminating long-lived access keys. In our enterprise AWS environment, I enforce this using a multi-tiered security model: Service Control Policies (SCPs) at the AWS Organizations level to define hard guardrails, IAM Permission Boundaries for delegated developer roles to prevent privilege escalation, OIDC for passwordless CI/CD authentication, and continuous pruning of unused permissions using IAM Access Analyzer and CloudTrail."
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Organization SCPs & IAM Permission Boundaries
Prevent privilege escalation and enforce organizational perimeter guardrails:
# Permission Boundary policy snippet attached to developer-created roles
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:*",
"dynamodb:*",
"sqs:*"
],
"Resource": "*"
},
{
"Effect": "Deny",
"Action": [
"iam:*",
"organizations:*"
],
"Resource": "*"
}
]
}
- Service Control Policies (SCPs): Deny critical operations across all member accounts (e.g. disabling CloudTrail, leaving the Organization, or creating IAM users outside us-east-1).
- IAM Permission Boundaries: Allow developers to create IAM roles for Lambda/ECS without permitting them to grant administrative privileges or bypass company security controls.
- Eliminate Long-Lived Static Keys: Enforce STS assume-role via GitHub Actions / GitLab CI OIDC federation and AWS IAM Identity Center (SSO) for human engineers.
2️⃣
Auditing Privilege Creep with Access Analyzer & Policy Simulation
Detect over-permissive access and safely down-scope production IAM policies:
# Generate report of unused services for a specific role
aws iam generate-service-last-accessed-details \
--arn arn:aws:iam::123456789012:role/jenkins-deployer
# Retrieve accessed details job output
aws iam get-service-last-accessed-details --job-id <job-id>
# List public and cross-account findings via Access Analyzer
aws accessanalyzer list-findings --analyzer-arn <analyzer-arn>
- IAM Access Analyzer: Continuously monitor resources (S3 buckets, KMS keys, IAM roles) shared outside your trusted AWS organization.
- Service Last Accessed Data: Review CloudTrail and Access Advisor data to identify permissions granted but never used in 90 days, then down-scope the policy.
- Policy Simulator: Test complex policies against proposed actions before applying changes to production.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Never use static access keys or wildcard Action:* permissions. Enforce organizational guardrails with SCPs, delegate role creation safely with IAM Permission Boundaries, and eliminate unused permissions using Access Analyzer."
⚡ 60-Second Elevator Pitch Talking Points
- Replace static IAM keys with short-lived STS tokens using OIDC role assumption for CI/CD pipelines.
- Attach IAM Permission Boundaries to delegated developer roles to permanently block privilege escalation.
- Continuously audit and down-scope permissions using AWS IAM Access Analyzer and CloudTrail event telemetry.
Advertisement