AWS IAM Access Analyzer

7.3easy start · #5 of 43
in Identity and Access Management Software
  • Free to practise onyes
  • Free trialnot on record
  • Well documentedyes
  • Runs where you workyes

Runs on Android, api, iOS, Web. Paid plans from $0.20/mo.

AWS IAM Access Analyzer helps teams review and refine permissions toward least privilege by identifying external, internal, and unused access to AWS resources. External findings monitor for new or changed permissions that allow public or cross-account access. Internal findings identify users and roles with access to S3, DynamoDB, or RDS, while unused-access findings can highlight roles, IAM user credentials, services, and actions that are not being used. The service can generate fine-grained IAM policies from activity recorded in AWS CloudTrail logs. Policy validation returns security warnings, errors, general warnings, and IAM best-practice suggestions. Teams can place custom policy checks in CI/CD pipelines before deployment. Access Analyzer also provides last-accessed information for services and actions from selected AWS services, and integrates with AWS Security Hub CSPM and Amazon EventBridge for findings workflows. AWS describes its permission assessment method as automated reasoning. Policy validation, policy generation, and external access analysis are provided at no additional charge; custom checks, unused-access analysis, and internal-access analysis have listed charges.

Who it is for

Access Analyzer suits AWS security teams reviewing access and refining permissions. It can also help compliance teams demonstrate access-control audit requirements and development teams check policies before deployment.

What is good

  • Identifies external, internal, and unused AWS access.
  • Generates policies from CloudTrail activity.
  • Custom policy checks can run in CI/CD pipelines.
  • Policy validation and external analysis have no additional charge.

What to know first

  • Custom policy checks are billed at $0.0020 per API call.
  • Unused access analysis costs $0.20 per IAM role or user per month.
  • Internal access analysis costs $9.00 per resource per Region per month.

Verdict

Access Analyzer covers several kinds of AWS permission review, with no additional charge for policy validation, policy generation, and external findings. Custom checks and unused or internal access analysis carry listed charges.

AWS IAM Access Analyzer plans and pricing

All plans
IAM policy validation Free Provided at no additional charge Validates policies against IAM best practices aws.amazon.com · 29 Sept 2026
Policy generation Free Provided at no additional charge Generates fine-grained policies based on access activity captured in logs aws.amazon.com · 29 Sept 2026
External access analyzer Free Provided at no additional charge Public and cross-account access findings for AWS resources aws.amazon.com · 29 Sept 2026
Custom policy checks Free $0.0020 per API call Charged based on the number of custom policy checks run through IAM Access Analyzer APIs aws.amazon.com · 29 Sept 2026
Unused access analyzer $0.20/mo $0.20 per IAM role or IAM user per month One analyzer across all Regions in a partition because IAM roles and users are global aws.amazon.com · 29 Sept 2026
Internal access analyzer $9/mo $9.00 per resource monitored per Region per month Monitors access to business-critical AWS resources within an AWS organization aws.amazon.com · 29 Sept 2026

Compared on identity and access management software

Supported clouds
AWS
Policy simulation
Yes
Deployment model
saas

Best AWS IAM Access Analyzer alternatives

See all 20