AWS Identity and Access Manager (IAM) Access Analyzer now supports unused access findings, internal access findings, and custom policy checks in the AWS GovCloud (US-East and US-West) Regions to help guide you towards least privilege.
IAM Access Analyzer continuously analyzes your accounts to identify unused access and surfaces findings to highlight unused roles, unused access keys for IAM users, and unused passwords for IAM users. For active IAM roles and users, the findings provide visibility into unused services and actions. With internal access findings, you can identify who within your AWS organization has access to your Amazon S3, Amazon DynamoDB, or Amazon Relational Database Service (RDS) resources. It uses automated reasoning to evaluate all identity policies, resource policies, service control policies (SCPs), and resource control policies (RCPs) to surface all IAM users and roles that have access to your selected critical resources. After the new analyzers are enabled in the IAM console, the updated dashboard highlights your AWS accounts and resources that have the most findings and provides a breakdown of findings by type. Security teams can respond to new findings in two ways: taking immediate action to fix unintended access, or setting up automated notifications through Amazon EventBridge to engage development teams for remediation.
Custom policy checks also use the power of automated reasoning to help security teams proactively detect nonconformant updates to policies. For example, IAM policy changes that are more permissive than their previous version. Security teams can use these checks to streamline their reviews, automatically approving policies that conform with their security standards, and inspecting more deeply when they don’t.
To learn more about IAM Access Analyzer:
- See the documentation
- Review the pricing
Categories:
Source: Amazon Web Services
Latest Posts
- Power Platform admin center – Manage external authentication provider governance [MC1210742]
![Power Platform admin center – Manage external authentication provider governance [MC1210742] 2 pexels merlin 11137997](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Dynamics 365 Contact Center – Debug issues in automatic assignment with enhanced logs [MC1210746]
![Dynamics 365 Contact Center - Debug issues in automatic assignment with enhanced logs [MC1210746] 3 pexels olly 3824771](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Dynamics 365 Contact Center – Debug routing issues with Application Insights dashboard [MC1210743]
![Dynamics 365 Contact Center - Debug routing issues with Application Insights dashboard [MC1210743] 4 pexels apasaric 325185](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Power Pages – Build modern single-page applications [MC1210747]
![Power Pages – Build modern single-page applications [MC1210747] 5 pexels cottonbro 5772130](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)

![Power Platform admin center – Manage external authentication provider governance [MC1210742] 2 pexels merlin 11137997](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-merlin-11137997-150x150.webp)
![Dynamics 365 Contact Center - Debug issues in automatic assignment with enhanced logs [MC1210746] 3 pexels olly 3824771](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-olly-3824771-150x150.webp)
![Dynamics 365 Contact Center - Debug routing issues with Application Insights dashboard [MC1210743] 4 pexels apasaric 325185](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-apasaric-325185-150x150.webp)
![Power Pages – Build modern single-page applications [MC1210747] 5 pexels cottonbro 5772130](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-cottonbro-5772130-150x150.webp)
![(Updated) New feature in Microsoft Viva Pulse to enable delegation [MC1104314] 7 (Updated) New feature in Microsoft Viva Pulse to enable delegation [MC1104314]](https://mwpro.co.uk/wp-content/uploads/2025/06/danbo-4326940_1920-96x96.webp)