AWS Identity and Access Manager (IAM) Access Analyzer now supports unused access findings, internal access findings, and custom policy checks in the AWS GovCloud (US-East and US-West) Regions to help guide you towards least privilege.
IAM Access Analyzer continuously analyzes your accounts to identify unused access and surfaces findings to highlight unused roles, unused access keys for IAM users, and unused passwords for IAM users. For active IAM roles and users, the findings provide visibility into unused services and actions. With internal access findings, you can identify who within your AWS organization has access to your Amazon S3, Amazon DynamoDB, or Amazon Relational Database Service (RDS) resources. It uses automated reasoning to evaluate all identity policies, resource policies, service control policies (SCPs), and resource control policies (RCPs) to surface all IAM users and roles that have access to your selected critical resources. After the new analyzers are enabled in the IAM console, the updated dashboard highlights your AWS accounts and resources that have the most findings and provides a breakdown of findings by type. Security teams can respond to new findings in two ways: taking immediate action to fix unintended access, or setting up automated notifications through Amazon EventBridge to engage development teams for remediation.
Custom policy checks also use the power of automated reasoning to help security teams proactively detect nonconformant updates to policies. For example, IAM policy changes that are more permissive than their previous version. Security teams can use these checks to streamline their reviews, automatically approving policies that conform with their security standards, and inspecting more deeply when they don’t.
To learn more about IAM Access Analyzer:
- See the documentation
- Review the pricing
Categories:
Source: Amazon Web Services
Latest Posts
- Power Apps – Configure offline profile using FetchXML editor [MC1247603]
![Power Apps - Configure offline profile using FetchXML editor [MC1247603] 2 pexels googledeepmind 25626433](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Power Apps – Enable online mode to access Dataverse for Canvas apps [MC1247618]
![Power Apps - Enable online mode to access Dataverse for Canvas apps [MC1247618] 3 pexels kerber 774731](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- (Updated) Microsoft Teams: Channel agent orchestration with GitHub, Asana, and Jira via Model Context Protocol (MCP) [MC1182703]
![(Updated) Microsoft Teams: Channel agent orchestration with GitHub, Asana, and Jira via Model Context Protocol (MCP) [MC1182703] 4 pexels pixabay 267684](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- (Updated) Agent Mode in Microsoft Copilot for PowerPoint for the web [MC1219792]
![(Updated) Agent Mode in Microsoft Copilot for PowerPoint for the web [MC1219792] 5 pexels jdgromov 4762727](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)

![Power Apps - Configure offline profile using FetchXML editor [MC1247603] 2 pexels googledeepmind 25626433](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-googledeepmind-25626433-150x150.webp)
![Power Apps - Enable online mode to access Dataverse for Canvas apps [MC1247618] 3 pexels kerber 774731](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-kerber-774731-150x150.webp)
![(Updated) Microsoft Teams: Channel agent orchestration with GitHub, Asana, and Jira via Model Context Protocol (MCP) [MC1182703] 4 pexels pixabay 267684](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-pixabay-267684-150x150.webp)
![(Updated) Agent Mode in Microsoft Copilot for PowerPoint for the web [MC1219792] 5 pexels jdgromov 4762727](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-jdgromov-4762727-150x150.webp)
![(Updated) New feature in Microsoft Viva Pulse to enable delegation [MC1104314] 7 (Updated) New feature in Microsoft Viva Pulse to enable delegation [MC1104314]](https://mwpro.co.uk/wp-content/uploads/2025/06/danbo-4326940_1920-96x96.webp)