AWS Security Hub now detects unused IAM permissions, roles, and credentials across AWS organizations, bringing identity risk management into the same unified console as threats and posture findings. A service-linked IAM Access Analyzer is automatically created in each member account when Security Hub is enabled, evaluating IAM principals against 90 days of actual access activity. The feature also provides on-demand generation of recommended least-privilege policies based on real usage patterns. These capabilities are included with Security Hub Essentials at no additional cost.

2m read timeFrom aws.amazon.com
Post cover image
167 Impressions