How to Use IAM Access Analyzer to Find Unused and External Access
Retrospective: this article looks back at events from December 2019, written in 2026 with the benefit of hindsight.
IAM Access Analyzer finds two kinds of risky access: resources shared outside your organization, and permissions nobody uses. Here is how to use both to reduce your attack surface.
Step 1: Create organization-level analyzers
From your delegated administrator (security tooling) account, create:
- An external access analyzer with the organization as the zone of trust, in each region you use.
- An unused access analyzer for the organization, choosing a tracking period (for example 90 days).
Step 2: Triage external access findings
For each finding, determine whether the access is intended:
- Intended (a known vendor or partner account): archive the finding with a reason, and create an archive rule for that account so future findings for it are handled consistently.
- Unintended: remove the access from the resource policy.
- Unknown: contact the resource owner; default to removing access if nobody claims it.
Pay special attention to findings showing public access.
Step 3: Reduce unused access
Unused access findings cover:
- Unused roles — delete or confirm still needed.
- Unused access keys and passwords — deactivate and remove.
- Unused permissions in roles and users — refine policies to what has actually been used.
Access Analyzer can recommend refined policies for some findings.
Step 4: Prevent new problems
Use policy validation in your infrastructure-as-code pipeline, and custom policy checks (for example, CheckNoPublicAccess) to fail deployments that would create public access.
Step 5: Report
Track open external access findings and unused access findings by account monthly. Both numbers should trend down.