AWS IAM Access Analyzer

B
B tier on Identity and Access Management SoftwareScore 7.2 · #5 of 41
Android app
Yes
Free plan
Yes
Paid plans from
$0.20/mo
Runs on
Android, api, iOS, Web

Summary

AWS IAM Access Analyzer helps teams review AWS permissions and work toward least privilege. It identifies external, internal, and unused access to AWS resources. External findings monitor for new or changed permissions that grant public or cross-account access, while internal findings identify users and roles with access to S3, DynamoDB, or RDS resources. Unused-access analysis can flag roles, IAM user access keys and passwords, services, and actions that are not in use. The service can generate fine-grained IAM policies from activity in AWS CloudTrail logs, validate policies with security warnings and best-practice suggestions, and provide last-accessed information for selected services and actions. Custom policy checks can be integrated into CI/CD pipelines before deployment. AWS says the analyzer uses automated reasoning to assess permissions. It integrates with AWS Security Hub CSPM and Amazon EventBridge for findings workflows. Policy validation, policy generation, and external access analysis are provided at no additional charge; custom checks, unused-access analysis, and internal-access analysis have listed usage-based charges.

Who it is for

AWS IAM Access Analyzer suits security teams reviewing and refining AWS permissions, and compliance teams demonstrating access-control audit requirements. Development teams can use custom policy checks in CI/CD workflows before policies are deployed.

What is good

  • Finds external, internal, and unused access.
  • Generates policies from CloudTrail activity.
  • Validates policies against IAM best practices.
  • Connects with Security Hub CSPM and EventBridge.

What to know first

  • Unused-access analysis costs $0.20 per role or user per month.
  • Internal analysis costs $9.00 per resource per Region per month.
  • Custom policy checks are charged per API call.

Everything Xiaomi review

AWS IAM Access Analyzer: the full review

AWS IAM Access Analyzer covers permission discovery, policy generation, and validation, with several capabilities available at no additional charge. Check the charges for custom checks and unused or internal access analysis when deciding which analyzers to use.

Overview

AWS IAM Access Analyzer helps organizations set, check, and refine AWS permissions with least privilege in mind. It examines external, internal, and unused access to AWS resources, using automated reasoning—a mathematical-logic approach—to assess permissions. Findings help security teams review access, while compliance teams can use the service to demonstrate access-control audit requirements.

The service supports several parts of the permissions lifecycle: monitoring resource exposure, identifying access to selected internal resources, reviewing unused access, generating policies from AWS CloudTrail activity, and validating policies against IAM best practices. It is a SaaS offering for AWS, not a general-purpose identity management product.

Key features

External, internal, and unused access findings

The external access analyzer continuously watches for new or changed resource permissions that allow public or cross-account access. Internal findings identify users and roles with access to S3, DynamoDB, or RDS resources. Unused access findings can identify unused roles, IAM user access keys and passwords, as well as unused services and actions.

Access Analyzer also provides last accessed information for AWS services and actions from select AWS services. This can give teams another source of context when reviewing whether access is still needed.

Policy generation and validation

Policy generation uses access activity captured in AWS CloudTrail logs to create fine-grained IAM policies. Policy validation checks policies for security warnings, errors, general warnings, and suggestions based on IAM best practices. Policy simulation is supported.

Workflow integrations and checks

Custom policy checks can be added to CI/CD pipelines to review policies before deployment. Access Analyzer integrates with AWS Security Hub CSPM and Amazon EventBridge, supporting findings analysis and notification workflows.

Pricing

AWS IAM Access Analyzer has a free plan, but not every analyzer capability is described as free. IAM policy validation, policy generation, and the external access analyzer are provided at no additional charge.

CapabilityPriceBilling detail
IAM policy validation0.00 USD per freeProvided at no additional charge
Policy generation0.00 USD per freeProvided at no additional charge
External access analyzer0.00 USD per freeProvided at no additional charge
Custom policy checks0.00 USD per month$0.0020 per API call; charged by the number of checks run through IAM Access Analyzer APIs
Unused access analyzer0.20 USD per month$0.20 per IAM role or IAM user per month; one analyzer across all Regions in a partition because roles and users are global
Internal access analyzer9.00 USD per month$9.00 per resource monitored per Region per month

The internal analyzer monitors access to business-critical AWS resources within an AWS organization. Review the applicable billing basis for each capability when estimating costs.

Platforms

Access Analyzer is listed for web, API, Android, and iOS. Its supported cloud is AWS, and its deployment model is SaaS. Listed identity capabilities include SAML 2.0, OAuth 2.0, and OIDC SSO protocols; FIDO2 authenticators, virtual authenticator apps, and RADIUS MFA methods; directory sync; and lifecycle provisioning. Adaptive access and adaptive access policies are not supported.

Who it's for

This service is aimed at teams responsible for AWS permissions rather than readers seeking broad app access controls across unrelated cloud platforms. Security teams can use its external, internal, and unused access findings to review and refine access. Compliance teams may find its policy checks and access visibility relevant when demonstrating access-control audit requirements. Development teams can use custom policy checks in CI/CD pipelines before deployment.

Organizations should also account for the distinct pricing of custom checks and internal or unused access analysis, alongside the no-additional-charge policy and external analysis capabilities.

Pros and cons

  • Pros: Covers public and cross-account exposure, selected internal resource access, and several forms of unused access.
  • Pros: Generates policies from CloudTrail activity and validates policies with warnings and best-practice suggestions.
  • Pros: Integrations with Security Hub CSPM and EventBridge, plus CI/CD support for custom checks, connect findings with operational workflows.
  • Cons: Focuses on AWS permissions and resources, so its scope is narrower than general-purpose identity management.
  • Cons: Internal and unused access analysis have usage-based billing details, while custom policy checks are billed per API call.
  • Cons: Adaptive access and adaptive access policies are not available.

Alternatives

For a broader look at adjacent categories, see Cloud Infrastructure Entitlement Management Software, Identity and Access Management Software, and Single Sign-On Software.

Other products to consider include C3M Cloud Control, Qualys TotalCloud, Palo Alto Networks Cortex Cloud API Security, Sysdig Secure, CrowdStrike Falcon Surface, FortiCNAPP, Rapid7 Surface Command, and SentinelOne Singularity Cloud Security.

Verdict

AWS IAM Access Analyzer is a focused permissions-analysis service for organizations already working with AWS. Its combination of exposure monitoring, internal and unused access findings, policy generation, and policy validation addresses multiple access-review tasks, with integrations and CI/CD checks extending those workflows. The main considerations are its AWS-specific scope and the separate charges associated with custom checks and some analyzer capabilities.

AWS IAM Access Analyzer plans and pricing

All plans
IAM policy validation Free Provided at no additional charge Validates policies against IAM best practices aws.amazon.com · 29 Sept 2026
Policy generation Free Provided at no additional charge Generates fine-grained policies based on access activity captured in logs aws.amazon.com · 29 Sept 2026
External access analyzer Free Provided at no additional charge Public and cross-account access findings for AWS resources aws.amazon.com · 29 Sept 2026
Custom policy checks Free $0.0020 per API call Charged based on the number of custom policy checks run through IAM Access Analyzer APIs aws.amazon.com · 29 Sept 2026
Unused access analyzer $0.20/mo $0.20 per IAM role or IAM user per month One analyzer across all Regions in a partition because IAM roles and users are global aws.amazon.com · 29 Sept 2026
Internal access analyzer $9/mo $9.00 per resource monitored per Region per month Monitors access to business-critical AWS resources within an AWS organization aws.amazon.com · 29 Sept 2026

Compared on identity and access management software

Supported clouds
AWSaws.amazon.com
Policy simulation
Yesaws.amazon.com
Deployment model
saasaws.amazon.com

Facts

Purpose
IAM Access Analyzer helps set, verify, and refine permissions on the journey toward least privilege.aws.amazon.com · 29 Sept 2026
Access findings
It analyzes external, internal, and unused access to AWS resources.aws.amazon.com · 29 Sept 2026
Policy generation
It generates fine-grained IAM policies from access activity captured in AWS CloudTrail logs.aws.amazon.com · 29 Sept 2026
Policy validation
Policy validation provides security warnings, errors, general warnings, and IAM best practice suggestions.aws.amazon.com · 29 Sept 2026
External monitoring
The external access analyzer continuously monitors for new or updated resource permissions that grant public or cross-account access.aws.amazon.com · 29 Sept 2026
Internal resource coverage
Internal access findings identify users and roles with access to S3, DynamoDB, or RDS resources.aws.amazon.com · 29 Sept 2026
Unused access
Unused access findings can identify unused roles, IAM user access keys, IAM user passwords, services, and actions.aws.amazon.com · 29 Sept 2026
Last accessed data
The service provides last accessed information for AWS services and actions from select AWS services.aws.amazon.com · 29 Sept 2026
Integrations
It integrates with AWS Security Hub CSPM and Amazon EventBridge for findings analysis and notification workflows.aws.amazon.com · 29 Sept 2026
Development workflow
Custom policy checks can be integrated into CI/CD pipelines to review policies before deployment.aws.amazon.com · 29 Sept 2026
Security method
The service uses automated reasoning technology, applying mathematical logic to assess AWS permissions.aws.amazon.com · 29 Sept 2026
Intended users
AWS describes the service as helping security teams review and refine access and compliance teams demonstrate access-control audit requirements.aws.amazon.com · 29 Sept 2026

Best AWS IAM Access Analyzer alternatives

See all 12

Where it ranks on Everything Xiaomi

Is AWS IAM Access Analyzer yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources