Description
An IAM Access Analyzer external access analyzer helps identify policies that share supported resources outside the zone of trust. Coverage depends on the analyzer’s Region and account or organization configuration.
Potential impact
Without this analysis or another review process, unintended external sharing may be discovered late.
Remediation
Configure AWS::AccessAnalyzer::Analyzer in the required Regions and review its findings. Use archive rules only for approved sharing; these rules do not change access permissions.
Examples
The examples add an account analyzer. Replace or remove the account and public-bucket archive exceptions to match actual approved sharing.
Before
yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: Configuration before adding an analyzer
Resources:
myuseeer:
Type: AWS::IAM::Group
Properties:
Path: "/"
After
yaml
AWSTemplateFormatVersion: "2010-09-09"
Resources:
Analyzer:
Type: "AWS::AccessAnalyzer::Analyzer"
Properties:
AnalyzerName: MyAccountAnalyzer
Type: ACCOUNT
Tags:
- Key: Kind
Value: Dev
ArchiveRules:
- # Archive findings for approved sharing with an AWS account.
RuleName: ArchiveTrustedAccountAccess
Filter:
- Property: "principal.AWS"
Eq:
- "123456789012"
- # Archive findings for S3 buckets approved for public access.
RuleName: ArchivePublicS3BucketsAccess
Filter:
- Property: "resource"
Eq:
- "arn:aws:s3:::docs-bucket"
- "arn:aws:s3:::clients-bucket"