AWS IAM Access Analyzer
- Android app
- Yes
- Free plan
- Yes
- Paid plans from
- $0.20/mo
- Runs on
- Android, api, iOS, Web
Summary
AWS IAM Access Analyzer helps teams review AWS permissions and work toward least privilege. It identifies external, internal, and unused access to AWS resources. External findings monitor for new or changed permissions that grant public or cross-account access, while internal findings identify users and roles with access to S3, DynamoDB, or RDS resources. Unused-access analysis can flag roles, IAM user access keys and passwords, services, and actions that are not in use. The service can generate fine-grained IAM policies from activity in AWS CloudTrail logs, validate policies with security warnings and best-practice suggestions, and provide last-accessed information for selected services and actions. Custom policy checks can be integrated into CI/CD pipelines before deployment. AWS says the analyzer uses automated reasoning to assess permissions. It integrates with AWS Security Hub CSPM and Amazon EventBridge for findings workflows. Policy validation, policy generation, and external access analysis are provided at no additional charge; custom checks, unused-access analysis, and internal-access analysis have listed usage-based charges.
Who it is for
AWS IAM Access Analyzer suits security teams reviewing and refining AWS permissions, and compliance teams demonstrating access-control audit requirements. Development teams can use custom policy checks in CI/CD workflows before policies are deployed.
What is good
- Finds external, internal, and unused access.
- Generates policies from CloudTrail activity.
- Validates policies against IAM best practices.
- Connects with Security Hub CSPM and EventBridge.
What to know first
- Unused-access analysis costs $0.20 per role or user per month.
- Internal analysis costs $9.00 per resource per Region per month.
- Custom policy checks are charged per API call.
Everything Xiaomi review
AWS IAM Access Analyzer: the full review
AWS IAM Access Analyzer covers permission discovery, policy generation, and validation, with several capabilities available at no additional charge. Check the charges for custom checks and unused or internal access analysis when deciding which analyzers to use.
Overview
AWS IAM Access Analyzer helps organizations set, check, and refine AWS permissions with least privilege in mind. It examines external, internal, and unused access to AWS resources, using automated reasoning—a mathematical-logic approach—to assess permissions. Findings help security teams review access, while compliance teams can use the service to demonstrate access-control audit requirements.
The service supports several parts of the permissions lifecycle: monitoring resource exposure, identifying access to selected internal resources, reviewing unused access, generating policies from AWS CloudTrail activity, and validating policies against IAM best practices. It is a SaaS offering for AWS, not a general-purpose identity management product.
Key features
External, internal, and unused access findings
The external access analyzer continuously watches for new or changed resource permissions that allow public or cross-account access. Internal findings identify users and roles with access to S3, DynamoDB, or RDS resources. Unused access findings can identify unused roles, IAM user access keys and passwords, as well as unused services and actions.
Access Analyzer also provides last accessed information for AWS services and actions from select AWS services. This can give teams another source of context when reviewing whether access is still needed.
Policy generation and validation
Policy generation uses access activity captured in AWS CloudTrail logs to create fine-grained IAM policies. Policy validation checks policies for security warnings, errors, general warnings, and suggestions based on IAM best practices. Policy simulation is supported.
Workflow integrations and checks
Custom policy checks can be added to CI/CD pipelines to review policies before deployment. Access Analyzer integrates with AWS Security Hub CSPM and Amazon EventBridge, supporting findings analysis and notification workflows.
Pricing
AWS IAM Access Analyzer has a free plan, but not every analyzer capability is described as free. IAM policy validation, policy generation, and the external access analyzer are provided at no additional charge.
| Capability | Price | Billing detail |
|---|---|---|
| IAM policy validation | 0.00 USD per free | Provided at no additional charge |
| Policy generation | 0.00 USD per free | Provided at no additional charge |
| External access analyzer | 0.00 USD per free | Provided at no additional charge |
| Custom policy checks | 0.00 USD per month | $0.0020 per API call; charged by the number of checks run through IAM Access Analyzer APIs |
| Unused access analyzer | 0.20 USD per month | $0.20 per IAM role or IAM user per month; one analyzer across all Regions in a partition because roles and users are global |
| Internal access analyzer | 9.00 USD per month | $9.00 per resource monitored per Region per month |
The internal analyzer monitors access to business-critical AWS resources within an AWS organization. Review the applicable billing basis for each capability when estimating costs.
Platforms
Access Analyzer is listed for web, API, Android, and iOS. Its supported cloud is AWS, and its deployment model is SaaS. Listed identity capabilities include SAML 2.0, OAuth 2.0, and OIDC SSO protocols; FIDO2 authenticators, virtual authenticator apps, and RADIUS MFA methods; directory sync; and lifecycle provisioning. Adaptive access and adaptive access policies are not supported.
Who it's for
This service is aimed at teams responsible for AWS permissions rather than readers seeking broad app access controls across unrelated cloud platforms. Security teams can use its external, internal, and unused access findings to review and refine access. Compliance teams may find its policy checks and access visibility relevant when demonstrating access-control audit requirements. Development teams can use custom policy checks in CI/CD pipelines before deployment.
Organizations should also account for the distinct pricing of custom checks and internal or unused access analysis, alongside the no-additional-charge policy and external analysis capabilities.
Pros and cons
- Pros: Covers public and cross-account exposure, selected internal resource access, and several forms of unused access.
- Pros: Generates policies from CloudTrail activity and validates policies with warnings and best-practice suggestions.
- Pros: Integrations with Security Hub CSPM and EventBridge, plus CI/CD support for custom checks, connect findings with operational workflows.
- Cons: Focuses on AWS permissions and resources, so its scope is narrower than general-purpose identity management.
- Cons: Internal and unused access analysis have usage-based billing details, while custom policy checks are billed per API call.
- Cons: Adaptive access and adaptive access policies are not available.
Alternatives
For a broader look at adjacent categories, see Cloud Infrastructure Entitlement Management Software, Identity and Access Management Software, and Single Sign-On Software.
Other products to consider include C3M Cloud Control, Qualys TotalCloud, Palo Alto Networks Cortex Cloud API Security, Sysdig Secure, CrowdStrike Falcon Surface, FortiCNAPP, Rapid7 Surface Command, and SentinelOne Singularity Cloud Security.
Verdict
AWS IAM Access Analyzer is a focused permissions-analysis service for organizations already working with AWS. Its combination of exposure monitoring, internal and unused access findings, policy generation, and policy validation addresses multiple access-review tasks, with integrations and CI/CD checks extending those workflows. The main considerations are its AWS-specific scope and the separate charges associated with custom checks and some analyzer capabilities.
AWS IAM Access Analyzer plans and pricing
All plansCompared on identity and access management software
- Supported clouds
- AWSaws.amazon.com
- Policy simulation
- Yesaws.amazon.com
- Deployment model
- saasaws.amazon.com
Facts
- Purpose
- IAM Access Analyzer helps set, verify, and refine permissions on the journey toward least privilege.aws.amazon.com · 29 Sept 2026
- Access findings
- It analyzes external, internal, and unused access to AWS resources.aws.amazon.com · 29 Sept 2026
- Policy generation
- It generates fine-grained IAM policies from access activity captured in AWS CloudTrail logs.aws.amazon.com · 29 Sept 2026
- Policy validation
- Policy validation provides security warnings, errors, general warnings, and IAM best practice suggestions.aws.amazon.com · 29 Sept 2026
- External monitoring
- The external access analyzer continuously monitors for new or updated resource permissions that grant public or cross-account access.aws.amazon.com · 29 Sept 2026
- Internal resource coverage
- Internal access findings identify users and roles with access to S3, DynamoDB, or RDS resources.aws.amazon.com · 29 Sept 2026
- Unused access
- Unused access findings can identify unused roles, IAM user access keys, IAM user passwords, services, and actions.aws.amazon.com · 29 Sept 2026
- Last accessed data
- The service provides last accessed information for AWS services and actions from select AWS services.aws.amazon.com · 29 Sept 2026
- Integrations
- It integrates with AWS Security Hub CSPM and Amazon EventBridge for findings analysis and notification workflows.aws.amazon.com · 29 Sept 2026
- Development workflow
- Custom policy checks can be integrated into CI/CD pipelines to review policies before deployment.aws.amazon.com · 29 Sept 2026
- Security method
- The service uses automated reasoning technology, applying mathematical logic to assess AWS permissions.aws.amazon.com · 29 Sept 2026
- Intended users
- AWS describes the service as helping security teams review and refine access and compliance teams demonstrate access-control audit requirements.aws.amazon.com · 29 Sept 2026
Best AWS IAM Access Analyzer alternatives
See all 12Where it ranks on Everything Xiaomi
Is AWS IAM Access Analyzer yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- aws.amazon.com/iam/access-analyzer/· checked 29 Sept 2026
- aws.amazon.com/iam/access-analyzer/features/· checked 29 Sept 2026
- aws.amazon.com/iam/access-analyzer/pricing/· checked 29 Sept 2026





