AdministratorAccess attached overly permissive
Critical
- Issue ID
- iam-prod-role
- Type
- Permission
- Date At
- 2026-04-15
IAM role iam-prod-role has AdministratorAccess policy attached. This grants unrestricted access to all AWS services and resources. Recommend scoping down to least-privilege permissions using service-specific policies.
- Policy: arn:aws:iam::aws:policy/AdministratorAccess
- Effect: Allow * on all resources
- Attached to: EKS Node Group (prod-eks-cluster)
- Compliance: CIS AWS 1.16 — Ensure IAM policies are attached only to groups or roles
- Risk: Credential compromise would grant full account takeover
Recommendation: Replace with scoped policies — AmazonEKSClusterPolicy, AmazonEKSWorkerNodePolicy, CloudWatchAgentServerPolicy








