AWSPlatform ChangesRetrospectives

IAM Access Analyzer Launches (Dec 2019): Finding Unintended Public and Cross-Account Access

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from December 2019, written in 2026 with the benefit of hindsight.

In December 2019, AWS launched IAM Access Analyzer. It used automated reasoning — mathematical analysis of policies — to identify resources that were shared with principals outside your account or organization.

What it did at launch

Access Analyzer examined resource-based policies on S3 buckets, IAM roles, KMS keys, Lambda functions and SQS queues. For each, it determined whether anyone outside your defined "zone of trust" — your account or your AWS Organization — could access it, and produced a finding describing who and how.

Unlike simple pattern checks, it reasoned about all possible requests a policy allows, catching subtle cases such as conditions that look restrictive but aren't.

Why it mattered

Cross-account access is powerful and common: vendors, partners and shared services all rely on it. But it is hard to audit manually across hundreds of policies. Many data exposures had come from resources unintentionally shared with "any AWS account."

How it grew

Access Analyzer expanded steadily:

  • More resource types (secrets, snapshots, ECR repositories and others).
  • Policy validation with best-practice checks while writing policies.
  • Policy generation from CloudTrail activity to create least-privilege policies.
  • Unused access findings identifying unused roles, access keys, passwords and permissions.
  • Custom policy checks to block risky policies in CI/CD pipelines.

In hindsight

Access Analyzer turned "who can reach this?" from a manual review into a continuous control. Combined with unused access analysis, it became one of the most practical tools for moving toward least privilege — the root issue behind breaches like Capital One.

iam access analyzer2019

More on this story