AWS IAM Access Analyzer
iPhone + Android
in Identity and Access Management Software
- Recognised40% of the score20
- Phone app26% of the score100
- Documented20% of the score96
- Free plan14% of the score100
- Free plan
- Yes
- Paid plans from
- $0.20/mo
- Runs on
- Android, api, iPhone, Web
Summary
AWS IAM Access Analyzer helps teams review and refine permissions on the path to least privilege. It identifies external, internal, and unused access to AWS resources. External analysis watches for new or changed permissions that allow public or cross-account access; internal findings identify users and roles with access to S3, DynamoDB, or RDS. Unused-access analysis can flag unused roles, IAM user keys and passwords, services, and actions. The service can generate fine-grained IAM policies from activity in CloudTrail logs, and policy validation returns security warnings, errors, and best-practice suggestions. Custom policy checks can be placed in CI/CD pipelines to review policies before deployment. It also provides last-accessed information for services and actions from selected AWS services, and integrates with AWS Security Hub CSPM and Amazon EventBridge for findings workflows. AWS says it uses automated reasoning, applying mathematical logic to assess permissions. Policy validation, policy generation, and external access analysis are provided at no additional charge; custom checks, unused-access analysis, and internal-access analysis have listed usage-based charges.
Who it is for
It suits security teams reviewing AWS permissions and compliance teams demonstrating access-control requirements. Teams can also use custom policy checks in a CI/CD review process.
What is good
- Finds external, internal, and unused AWS access
- Generates policies from CloudTrail activity
- Validates policies with security warnings and suggestions
- Policy validation, generation, and external analysis are no-charge
What to know first
- Custom policy checks are charged per API call
- Unused-access analysis has a per-user or role charge
- Internal analysis is charged per resource and Region
Verdict
IAM Access Analyzer covers several permission-review tasks, including monitoring external access and identifying unused access. Check the listed usage charges for the specific analysis features you plan to use.
AWS IAM Access Analyzer plans and pricing
All plansCompared on identity and access management software
- Supported clouds
- AWSaws.amazon.com
- Policy simulation
- Yesaws.amazon.com
- Deployment model
- saasaws.amazon.com
Facts
- Purpose
- IAM Access Analyzer helps set, verify, and refine permissions on the journey toward least privilege.aws.amazon.com · 29 Sept 2026
- Access findings
- It analyzes external, internal, and unused access to AWS resources.aws.amazon.com · 29 Sept 2026
- Policy generation
- It generates fine-grained IAM policies from access activity captured in AWS CloudTrail logs.aws.amazon.com · 29 Sept 2026
- Policy validation
- Policy validation provides security warnings, errors, general warnings, and IAM best practice suggestions.aws.amazon.com · 29 Sept 2026
- External monitoring
- The external access analyzer continuously monitors for new or updated resource permissions that grant public or cross-account access.aws.amazon.com · 29 Sept 2026
- Internal resource coverage
- Internal access findings identify users and roles with access to S3, DynamoDB, or RDS resources.aws.amazon.com · 29 Sept 2026
- Unused access
- Unused access findings can identify unused roles, IAM user access keys, IAM user passwords, services, and actions.aws.amazon.com · 29 Sept 2026
- Last accessed data
- The service provides last accessed information for AWS services and actions from select AWS services.aws.amazon.com · 29 Sept 2026
- Integrations
- It integrates with AWS Security Hub CSPM and Amazon EventBridge for findings analysis and notification workflows.aws.amazon.com · 29 Sept 2026
- Development workflow
- Custom policy checks can be integrated into CI/CD pipelines to review policies before deployment.aws.amazon.com · 29 Sept 2026
- Security method
- The service uses automated reasoning technology, applying mathematical logic to assess AWS permissions.aws.amazon.com · 29 Sept 2026
- Intended users
- AWS describes the service as helping security teams review and refine access and compliance teams demonstrate access-control audit requirements.aws.amazon.com · 29 Sept 2026
Best AWS IAM Access Analyzer alternatives
See all 12Where it ranks on Samsung Mobile US Press
Is AWS IAM Access Analyzer yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- aws.amazon.com/iam/access-analyzer/· checked 29 Sept 2026
- aws.amazon.com/iam/access-analyzer/features/· checked 29 Sept 2026
- aws.amazon.com/iam/access-analyzer/pricing/· checked 29 Sept 2026




