diff --git a/checks/check116 b/checks/check116 index a70114ae..fb74e2db 100644 --- a/checks/check116 +++ b/checks/check116 @@ -24,6 +24,11 @@ check116(){ textFail "$user has policy directly attached " C116_NUM_USERS=$(expr $C116_NUM_USERS + 1) fi + USER_POLICY=$($AWSCLI iam list-user-policies --output text $PROFILE_OPT --region $REGION --user-name $user) + if [[ $USER_POLICY ]]; then + textFail "$user has inline policy directly attached " + C116_NUM_USERS=$(expr $C116_NUM_USERS + 1) + fi done if [[ $C116_NUM_USERS -eq 0 ]]; then textPass "No policies attached to users."