Description
IAM Access Analyzer external-access analysis helps identify supported resource policies that allow access outside an account or organization’s zone of trust. Missing required analysis can delay discovery of excessive sharing.
Findings describe access permitted by policies, not evidence of compromise or automatic blocking. Organization analysis trusts accounts inside the organization, so review internal access separately where needed.
Potential impact
- External sharing beyond the intended scope can remain unnoticed.
- Unnecessary access can persist if findings are not acted on.
Remediation
- Configure external-access analyzers for the required Regions and trust boundaries. For organization analysis, prepare the management account or registered delegated administrator and required organization integration.
- Check supported resource coverage and review, remediate or document intended sharing. Use actual request logs and other access controls alongside the analysis.
Examples
Add the after resource to the organization configuration shown before it. Provide the actual management or delegated-administrator permissions and target Region.
Before
hcl
resource "aws_organizations_organization" "example" {
aws_service_access_principals = ["access-analyzer.amazonaws.com"]
}
After
hcl
resource "aws_accessanalyzer_analyzer" "example" {
depends_on = [aws_organizations_organization.example]
analyzer_name = "example"
type = "ORGANIZATION"
}
Explanation:
- Before: Prepares organization access for the service without creating an analyzer itself.
- After: Creates an external-access analyzer with the organization as its trust zone. Review finding handling and coverage of other Regions separately.