A security engineer is troubleshooting an access issue for an IAM user named 'AppUser' in an AWS account. 'AppUser' is a member of the 'Developers' IAM group and has a directly attached IAM policy. The 'Developers' group also has an attached IAM policy. Additionally, a permissions boundary is attached to 'AppUser'. The user is trying to perform an action that they believe should be allowed, but they are receiving an 'Access Denied' error. In which order does IAM evaluate these policies to determine access?
- AExplicit Deny -> SCP -> Resource-Based Policy -> Identity-Based Policy (User/Group) -> Permissions Boundary -> Implicit Deny
- BPermissions Boundary -> User Policy -> Group Policy -> Resource Policy
- CIAM policies (User/Group) -> Permissions Boundary -> Resource Policy -> Explicit Deny
- DResource Policy -> Group Policy -> User Policy -> Permissions Boundary
Show answer & explanationAnswer & explanation
Correct answer: A. Explicit Deny -> SCP -> Resource-Based Policy -> Identity-Based Policy (User/Group) -> Permissions Boundary -> Implicit Deny
AWS IAM policy evaluation follows a specific order: first, any explicit deny takes precedence. Then, Service Control Policies (SCPs) are evaluated. Next, resource-based policies are evaluated. Following this, identity-based policies (attached to users, groups, or roles) are evaluated. Finally, a permissions boundary sets the maximum permissions, and if no explicit allow is found, an implicit deny occurs. This comprehensive order ensures consistent access decisions.
Why the other options are wrong
- B. This order is incorrect and misses critical policy types like SCPs and the precedence of explicit deny.
- C. This order is incorrect, as explicit deny has the highest precedence, and permissions boundaries are evaluated after identity-based policies but before the final implicit deny.
- D. This order is incorrect and misses explicit deny, SCPs, and places permissions boundary incorrectly.
IAM Policy Evaluation Order
The specific sequence in which AWS IAM evaluates different policy types to determine whether a principal is allowed or denied access to a resource.
- Explicit Deny always overrides Explicit Allow.
- SCPs set the maximum permissions for an account.
- Permissions boundaries set the maximum permissions for an IAM entity.
- Implicit Deny occurs if no policy explicitly allows an action.
Memory trick: Think of a 'series of security checkpoints' where each type of policy is a gatekeeper, with Explicit Deny being the ultimate 'veto'.