AWS AWSEC2: Clarified IAM tag manipulation risk warning
Summary
Changed 'in order to bypass' to 'to bypass' in tag-based access control warning.
Security assessment
Simplifies phrasing without altering the security warning about IAM tag manipulation risks.
Evidence
+Specifying a **Name** while launching an instance creates a tag and requires the `ec2:CreateTags` action. Be careful about granting users permission to use the `ec2:CreateTags` action, because doing so limits your ability to use the `aws:ResourceTag` condition key to restrict their use of other resources. If you grant users permission to use the `ec2:CreateTags` action, they can change a resource's tag to bypass those restrictions. For more information, see [Control access using attribute-based access](./iam-policies-for-amazon-ec2.html#control-access-with-tags).
Diff
diff --git a/AWSEC2/latest/UserGuide/iam-policies-ec2-console.md b/AWSEC2/latest/UserGuide/iam-policies-ec2-console.md index bb9858724..2eb995adb 100644 --- a//AWSEC2/latest/UserGuide/iam-policies-ec2-console.md +++ b//AWSEC2/latest/UserGuide/iam-policies-ec2-console.md @@ -171 +171 @@ You can add API actions to your policy to provide more options for users, for ex -Specifying a **Name** while launching an instance creates a tag and requires the `ec2:CreateTags` action. Be careful about granting users permission to use the `ec2:CreateTags` action, because doing so limits your ability to use the `aws:ResourceTag` condition key to restrict their use of other resources. If you grant users permission to use the `ec2:CreateTags` action, they can change a resource's tag in order to bypass those restrictions. For more information, see [Control access using attribute-based access](./iam-policies-for-amazon-ec2.html#control-access-with-tags). +Specifying a **Name** while launching an instance creates a tag and requires the `ec2:CreateTags` action. Be careful about granting users permission to use the `ec2:CreateTags` action, because doing so limits your ability to use the `aws:ResourceTag` condition key to restrict their use of other resources. If you grant users permission to use the `ec2:CreateTags` action, they can change a resource's tag to bypass those restrictions. For more information, see [Control access using attribute-based access](./iam-policies-for-amazon-ec2.html#control-access-with-tags).