This is a follow on from How can i enforce file type uploads with an AWS S3 bucket policy
When applying the bucket policy:
{ \"Version\":\"2008-10
It's not possible to use groups in Principal at the moment. See https://forums.aws.amazon.com/message.jspa?messageID=356160
Principal