IAM Access Analyzer
IAM Access Analyzer is a tool within AWS that helps to identify the resources in your AWS account that are shared with an external entity or that are not in use and, therefore, do not follow the principle of least privilege. It does this by analyzing policies and reporting on any that grant public or cross-account access. This tool is vital for maintaining a secure AWS environment by ensuring that only intended users have access to your resources, especially with external entities that you do not have full control or governance over.
Figure 3.4 – IAM Access Analyzer
Setting up IAM Access Analyzer involves enabling it in the IAM console and reviewing the output. Once enabled, it automatically analyzes policies and generates comprehensive findings. IAM Access Analyzer is regional, so you need to create an audit run for each region in which you operate. It is also worthwhile running it for all regions that you have access to...