Review IAM Access Analyzer configuration

Analyze external access to supported resources and make findings part of operational review.

Description

IAM Access Analyzer external-access analysis helps identify supported resource policies that allow access outside an account or organization’s zone of trust. Missing required analysis can delay discovery of excessive sharing.

Findings describe access permitted by policies, not evidence of compromise or automatic blocking. Organization analysis trusts accounts inside the organization, so review internal access separately where needed.

Potential impact

  • External sharing beyond the intended scope can remain unnoticed.
  • Unnecessary access can persist if findings are not acted on.

Remediation

  • Configure external-access analyzers for the required Regions and trust boundaries. For organization analysis, prepare the management account or registered delegated administrator and required organization integration.
  • Check supported resource coverage and review, remediate or document intended sharing. Use actual request logs and other access controls alongside the analysis.

Examples

Add the after resource to the organization configuration shown before it. Provide the actual management or delegated-administrator permissions and target Region.

Before

hcl
resource "aws_organizations_organization" "example" {
  aws_service_access_principals = ["access-analyzer.amazonaws.com"]
}

After

hcl
resource "aws_accessanalyzer_analyzer" "example" {
  depends_on    = [aws_organizations_organization.example]
  analyzer_name = "example"
  type          = "ORGANIZATION"
}

Explanation:

  • Before: Prepares organization access for the service without creating an analyzer itself.
  • After: Creates an external-access analyzer with the organization as its trust zone. Review finding handling and coverage of other Regions separately.

References