IAM policies should not be granted directly to users.
CIS recommends that you apply IAM policies directly to groups and roles but not users. Assigning privileges at the group or role level reduces the complexity of access management as the number of users grow. Reducing access management complexity might in turn reduce opportunity for a principal to inadvertently receive or retain excessive privileges.
Impact
Recommended Actions
Follow the appropriate remediation steps below to resolve the issue.