IAM Access Analyzer Launches (Dec 2019): Finding Unintended Public and Cross-Account Access
Retrospective: this article looks back at events from December 2019, written in 2026 with the benefit of hindsight.
In December 2019, AWS launched IAM Access Analyzer. It used automated reasoning — mathematical analysis of policies — to identify resources that were shared with principals outside your account or organization.
What it did at launch
Access Analyzer examined resource-based policies on S3 buckets, IAM roles, KMS keys, Lambda functions and SQS queues. For each, it determined whether anyone outside your defined "zone of trust" — your account or your AWS Organization — could access it, and produced a finding describing who and how.
Unlike simple pattern checks, it reasoned about all possible requests a policy allows, catching subtle cases such as conditions that look restrictive but aren't.
Why it mattered
Cross-account access is powerful and common: vendors, partners and shared services all rely on it. But it is hard to audit manually across hundreds of policies. Many data exposures had come from resources unintentionally shared with "any AWS account."
How it grew
Access Analyzer expanded steadily:
- More resource types (secrets, snapshots, ECR repositories and others).
- Policy validation with best-practice checks while writing policies.
- Policy generation from CloudTrail activity to create least-privilege policies.
- Unused access findings identifying unused roles, access keys, passwords and permissions.
- Custom policy checks to block risky policies in CI/CD pipelines.
In hindsight
Access Analyzer turned "who can reach this?" from a manual review into a continuous control. Combined with unused access analysis, it became one of the most practical tools for moving toward least privilege — the root issue behind breaches like Capital One.
- How to Use IAM Access Analyzer to Find Unused and External Access How-To & Hardening
- Quarterly External Access Review Checklist for AWS How-To & Hardening
- CIO Brief: Who Outside Your Company Can Reach Your AWS Resources? CIO Briefings