IAM roles rightsizing

0

How should one be rightsizing IAM roles? Is there a tool i could use?

gefragt vor 2 Jahren259 Aufrufe
2 Antworten
0
Akzeptierte Antwort

Hi, please take a look at IAM access analyser. It provides the following capabilities:

  • helps identify resources in your organization and accounts that are shared with an external entity. This lets you identify unintended access to your resources and data.
  • validates IAM policies against policy grammar and best practices.
  • generates IAM policies based on access activity in your AWS CloudTrail logs. You can use the generated policy to refine an entity's permissions by attaching it to an IAM user or role. In addition, this blog talks through a solution that provides continuous profiling of IAM usage with automated adjustments of permissions using AWS Config and CloudKnox.
AWS
Kash
beantwortet vor 2 Jahren
0

Hi,

if by rightsizing, you mean a way to analyze and optimize IAM policies, you can look at IAM Access Analyzer ... https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html

It generates findings based on best practices and CloudTrail logs, which lets you know if your policies are permissive, and enables you to fine-tune them.

AWS
beantwortet vor 2 Jahren

Du bist nicht angemeldet. Anmelden um eine Antwort zu veröffentlichen.

Eine gute Antwort beantwortet die Frage klar, gibt konstruktives Feedback und fördert die berufliche Weiterentwicklung des Fragenstellers.

Richtlinien für die Beantwortung von Fragen