AWS > IAM >

CloudShell Full Access Restricted

HIGH
Source
CloudSploit
ID
cloudshell-full-access-restricted

CloudShell Full Access Restricted

Ensures that access to AWSCloudShellFullAccess is restricted.

Access to the AWSCloudShellFullAccess policy should be restricted, as it presents a potential channel for data exfiltration by privileged users.

Detach the AWSCloudShellFullAccess policy from all IAM users, groups, and roles, and replace with a more restrictive policy if CloudShell access is required.