IAM Access Analyzer not enabled

Configure an analyzer to review external sharing permissions.

Description

An IAM Access Analyzer external access analyzer helps identify policies that share supported resources outside the zone of trust. Coverage depends on the analyzer’s Region and account or organization configuration.

Potential impact

Without this analysis or another review process, unintended external sharing may be discovered late.

Remediation

Configure AWS::AccessAnalyzer::Analyzer in the required Regions and review its findings. Use archive rules only for approved sharing; these rules do not change access permissions.

Examples

The examples add an account analyzer. Replace or remove the account and public-bucket archive exceptions to match actual approved sharing.

Before

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: Configuration before adding an analyzer
Resources:
  myuseeer:
    Type: AWS::IAM::Group
    Properties:
      Path: "/"

After

yaml
AWSTemplateFormatVersion: "2010-09-09"
Resources:
  Analyzer:
    Type: "AWS::AccessAnalyzer::Analyzer"
    Properties:
      AnalyzerName: MyAccountAnalyzer
      Type: ACCOUNT
      Tags:
        - Key: Kind
          Value: Dev
      ArchiveRules:
        - # Archive findings for approved sharing with an AWS account.
          RuleName: ArchiveTrustedAccountAccess
          Filter:
            - Property: "principal.AWS"
              Eq:
                - "123456789012"
        - # Archive findings for S3 buckets approved for public access.
          RuleName: ArchivePublicS3BucketsAccess
          Filter:
            - Property: "resource"
              Eq:
                - "arn:aws:s3:::docs-bucket"
                - "arn:aws:s3:::clients-bucket"

References