Glossary

    IAM Access Analyzer

    Identity & Access

    IAM Access Analyzer helps you identify resources in your account that are shared with an external entity. It uses automated reasoning (mathematical proofs) to analyze resource-based policies on S3 buckets, IAM roles, KMS keys, Lambda functions, SQS queues, and Secrets Manager secrets.

    Key Features

    • External Access Findings: flags resources accessible from outside your account or organization
    • Unused Access Analysis: identifies unused roles, unused access keys, unused permissions, and unused services
    • Policy Generation: generates least-privilege policies based on CloudTrail access activity
    • Policy Validation: checks policies against AWS best practices and grammar rules
    • Custom Policy Checks: validate policies against your security standards before deployment

    How It Works

    Access Analyzer uses Zelkova, an automated reasoning engine, to mathematically prove whether a policy grants access to external principals. This is not pattern matching - it's formal verification, guaranteeing no false negatives for supported resource types.

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.