Ensure that customer managed IAM policy does not grant full administrative rights

IAM policy should not grant administrative access to everyone as it violates the principle of least privilege.