AWS IAM

When you have enabled the Identity and Access Management (IAM) data synchronization in Settings > General > Data synchronization, you can view AWS IAM on the left navigation. For details about the settings, refer to General Settings.

Principals

On the Principals page, all principals in the tenant are listed in the table. Principals represent one or more identities that have been authenticated to AWS.

  • Principal name – The display name of the principal.

  • ARN – The Amazon Resource Name (ARN) of the principal.

  • Type – The type of the principal.

  • Resources – The number of resources to which this principal has been granted access. Click the number link to view details on the Access report page, where you can view the resource ID, the number of attached policies, and the access level or role this principal has to the resource. Click the policy number link to view the policy name and access level in the right panel. Switch to the Group membership tab of the Access report page to view the groups where this principal is a member, as well as the number of members and number of resources for each group.

  • Last activity – The last activity time of the principal.

The following actions are available on the Principals page.

  • Filter – Click Filter in the upper-right corner of the table, and the Filter window appears in the right pane. All columns that are available for the filter are listed below. Click the down arrow button to the right of a column to show the text box or selectable options. Enter keywords in the text box and/or select desired options to define the filter conditions.

    You can also click Reset to default to clear your input and selections and reset the filters to their default state.

    Click Apply changes to filter items displayed in the table based on the configured filters.

  • Manage columns – Click Columns in the upper-right corner of the table, and the drop-down list where all available columns are displayed appears. Select the columns that you want to display in the table, and click Apply to apply the column selection. You can also choose Select all to show all columns in the table, or click Reset to reset the column selection.

  • Refresh – Click Refresh to view the latest data on this page.

  • Export – You can export the principals using one of the following methods:

    • Click Export for all above the table to export all records of the current data scope.

    • Filter the records and then click Export for all to export the report of the filtered records.

    • Select one or multiple records and then click Export for selected items to export the selected records.

    In the export drop-down list, select Export summary report to export the summary report of the records, or select Export access report to export both the detailed record report and access report for the records.

    In the export window, a default report name is automatically filled in, and you can edit it if desired. Click Export in the window to start the export.

    When the export process begins, you can monitor its progress by navigating to Job monitor > Download center or by clicking the Download center link in the prompted message.

  • View access report – Click the ellipsis button to the right of a principal record and select Access report to view the access report of the principal.

    • In the Resources tab, you can view the resource ID, the number of attached policies, and the access level or role this principal has to the resource.

    • In the Group membership tab, you can view the groups where this principal is a member, as well as the number of members and number of resources for each group.

Resources

On the Resources page, all resources in the tenant are listed in the table.

  • Resource ID – The ID of the resource.

  • ARN – The Amazon Resource Name (ARN) of the resource.

  • Type – The resource type.

  • Tags – The tags applied to the resource. Click the tag to view the tag details in the right pane.

  • Region – The region where the resource is located.

  • Service – The service to which the resource belongs.

  • Principals with access – The number of external users with access and the total number of principals with access. Click the number link to access the View permissions page. On the View permissions page, you can view the principal name, type, the number of attached policies, and the access level this principal has to this resource. Click the policy number link to view the policy name and access level in the right panel.

  • Owner – The owner of the resource.

  • Exposure level – The exposure level of the resource, High, Medium, or Low. Click it to view the matched exposure rule.

    The exposure level is calculated based on the exposure level settings. For details, refer to Exposure Definitions.

  • Last discovered time – The time when this resource is discovered.

The following actions are available on the Resources page.

  • Filter – Click Filter in the upper-right corner of the table, and the Filter window appears in the right pane. All columns that are available for the filter are listed below. Click the down arrow button to the right of a column to show the text box or selectable options. Enter keywords in the text box and/or select desired options to define the filter conditions.

    You can also click Reset to default to clear your input and selections and reset the filters to their default state.

    Click Apply changes to filter items displayed in the table based on the configured filters.

  • Manage columns – Click Columns in the upper-right corner of the table, and the drop-down list where all available columns are displayed appears. Select the columns that you want to display in the table, and click Apply to apply the column selection. You can also choose Select all to show all columns in the table, or click Reset to reset the column selection.

  • Refresh – Click Refresh to view the latest data on this page.

  • Export – You can export the principals using one of the following methods:

    • Click Export for all above the table to export all records of the current data scope.

    • Filter the records and then click Export for all to export the report of the filtered records.

    • Select one or multiple records and then click Export for selected items to export the selected records.

    In the export drop-down list, select Export summary report to export the summary report of the records, or select Export access report to export both the detailed record report and access report for the records.

    In the export window, a default report name is automatically filled in, and you can edit it if desired. Click Export in the window to start the export.

    When the export process begins, you can monitor its progress by navigating to Job monitor > Download center or by clicking the Download center link in the prompted message.

  • View access report – Click the ellipsis button to the right of a resource record and select Access report to view the access report of the resource. On the View permissions page, you can view the principal name, type, the number of attached policies, and the access level this principal has to this resource. Click the policy number link to view the policy name and access level in the right panel.

Policies

On the Policies page, all policies in the tenant are listed in the table.

  • Policy name – The name of the policy.

  • ARN – The Amazon Resource Name (ARN) of the policy.

  • Description – The description of the policy.

  • Type – The policy type.

  • Creation time – The time when the policy is created.

  • Attached entities – The number of entities to which this policy is attached. Click the number link to access the Entities tab of the Access report page, where you can view the entity name, type, and last activity.

  • Resources – The number of resources to which this policy is attached. Click the number link to access the Resources tab of the Access report page, where you can view the resource ID, type, service, and access level this policy has to the resource. Click the access level to view the actions allowed in the right panel.

The following actions are available on the Policies page.

  • Filter – Click Filter in the upper-right corner of the table, and the Filter window appears in the right pane. All columns that are available for the filter are listed below. Click the down arrow button to the right of a column to show the text box or selectable options. Enter keywords in the text box and/or select desired options to define the filter conditions.

    You can also click Reset to default to clear your input and selections and reset the filters to their default state.

    Click Apply changes to filter items displayed in the table based on the configured filters.

  • Manage columns – Click Columns in the upper-right corner of the table, and the drop-down list where all available columns are displayed appears. Select the columns that you want to display in the table, and click Apply to apply the column selection. You can also choose Select all to show all columns in the table, or click Reset to reset the column selection.

  • Refresh – Click Refresh to view the latest data on this page.

  • Export – You can export the principals using one of the following methods:

    • Click Export for all above the table to export all records of the current data scope.

    • Filter the records and then click Export for all to export the report of the filtered records.

    • Select one or multiple records and then click Export for selected items to export the selected records.

    In the export drop-down list, select Export summary report to export the summary report of the records, or select Export access report to export both the detailed record report and access report for the records.

    In the export window, a default report name is automatically filled in, and you can edit it if desired. Click Export in the window to start the export.

    When the export process begins, you can monitor its progress by navigating to Job monitor > Download center or by clicking the Download center link in the prompted message.

  • View access report – Click the ellipsis button to the right of a policy record and select Access report to view the access report of the policy.

    • In the Resources tab, you can view the resource ID, type, service, and access level this policy has to the resource. Click the access level to view the actions allowed in the right panel.

    • In the Entities tab, you can view the entity name, type, and last activity.