Deleting an IAM user group - Amazon Identity and Access Management
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China.

Deleting an IAM user group

When you delete a user group in the Amazon Web Services Management Console, the console automatically removes all group members, detaches all attached managed policies, and deletes all inline policies. However, because IAM does not automatically delete policies that refer to the user group as a resource, you must be careful when you delete a user group. Before you delete your user group, you must manually check all of your policies to find any policies that mention the group by name. For example, John, the Test Team manager, has a policy attached to his IAM user entity that lets him add and remove users from the Test user group. If an administrator deletes the group, the administrator must also delete the policy attached to John. Otherwise, if the administrator recreates the deleted group and give it the same name, John's permissions remain in place, even if he left the Test Team.

To find policies that refer to a user group as a resource

  1. From the navigation pane of the IAM console, choose Policies.

  2. Sort by the Type column to find your Customer managed custom policies.

  3. Choose the policy name of the policy to delete.

  4. Choose the Permissions tab, and then choose Policy summary.

  5. Choose IAM from the list of services, if it exists.

  6. Look for the name of your user group in the Resource column.

  7. Choose Delete policy to delete the policy.

In contrast, when you use the Amazon CLI, Tools for Windows PowerShell, or Amazon API to delete a user group, you must first remove the users in the group. Then delete any inline policies embedded in the user group. Next, detach any managed policies that are attached to the group. Only then can you delete the user group itself.

Deleting an IAM user group (console)

You can delete an IAM user group from the Amazon Web Services Management Console.

To delete an IAM user group (console)

  1. Sign in to the Amazon Web Services Management Console and open the IAM console at https://console.amazonaws.cn/iam/.

  2. In the navigation pane, choose User groups.

  3. In the list of user groups, select the check box next to the names of the user groups to delete. You can use the search box to filter the list of user groups by type, permissions, and user group name.

  4. Choose Delete.

  5. In the confirmation box, if you want to delete a single user group, type the user group name and choose Delete. If you want to delete multiple user groups, type the number of user groups to delete followed by user groups and choose Delete. For example, if you delete three user groups, type 3 user groups.

Deleting an IAM user group (Amazon CLI)

You can delete an IAM user group from the Amazon CLI.

To delete an IAM user group (Amazon CLI)

  1. Remove all users from the user group.

  2. Delete all inline policies embedded in the user group.

  3. Detach all managed policies attached to the user group.

  4. Delete the user group.

Deleting an IAM user group (Amazon API)

You can use the Amazon API to delete an IAM user group.

To delete an IAM user group (Amazon API)

  1. Remove all users from the user group.

  2. Delete all inline policies embedded in the user group.

  3. Detach all managed policies attached to the user group.

  4. Delete the user group.