AWSHow-To & HardeningRetrospectives

How to Use IAM Access Analyzer to Find Unused and External Access

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from December 2019, written in 2026 with the benefit of hindsight.

IAM Access Analyzer finds two kinds of risky access: resources shared outside your organization, and permissions nobody uses. Here is how to use both to reduce your attack surface.

Step 1: Create organization-level analyzers

From your delegated administrator (security tooling) account, create:

  • An external access analyzer with the organization as the zone of trust, in each region you use.
  • An unused access analyzer for the organization, choosing a tracking period (for example 90 days).

Step 2: Triage external access findings

For each finding, determine whether the access is intended:

  • Intended (a known vendor or partner account): archive the finding with a reason, and create an archive rule for that account so future findings for it are handled consistently.
  • Unintended: remove the access from the resource policy.
  • Unknown: contact the resource owner; default to removing access if nobody claims it.

Pay special attention to findings showing public access.

Step 3: Reduce unused access

Unused access findings cover:

  • Unused roles — delete or confirm still needed.
  • Unused access keys and passwords — deactivate and remove.
  • Unused permissions in roles and users — refine policies to what has actually been used.

Access Analyzer can recommend refined policies for some findings.

Step 4: Prevent new problems

Use policy validation in your infrastructure-as-code pipeline, and custom policy checks (for example, CheckNoPublicAccess) to fail deployments that would create public access.

Step 5: Report

Track open external access findings and unused access findings by account monthly. Both numbers should trend down.

iam access analyzer unused accessIAM Access Analyzer2019

More on this story