Reports for Every Cloud
Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.
58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results

Identity & Access Management Best Practices
53 controls
15 services covered
Covers least-privilege controls across IAM, IAM Identity Center, IAM Access Analyzer, Cognito, AppSync authorization, Resource Access Manager sharing, Bedrock AgentCore, and CloudFormation service roles — including passwords, MFA, access keys, and high-risk permissions.
What we check
IAM Identity Center Permission Sets10
- No SSO Permission Set with access to blocked actions on KMS
- No SSO Permission Set with Full Administrator Permissions "*:*"
- No SSO Permission Set with Unrestricted iam:PassRole Permissions
- No SSO Permission Set with Sensitive IAM Access
- No SSO Permission Set with Access to Invoke Any Lambda Function
- No SSO Permission Set with Unrestricted S3 Access
- No SSO Permission Set with Unrestricted S3 Read Access
- No SSO Permission Set with Access to Get All Secrets
- No SSO Permission Set with all service access or wildcard service access
- No SSO Permission Set with Unrestricted sts:AssumeRole Permissions
IAM Users and Access Keys9
- IAM Access Keys Are Rotated every 90 Days
- No Inline IAM Policies Attached
- Do Not Create Access Keys During Initial Setup for IAM Users with Console Password
- No IAM Users with Administrator Privileges without MFA
- No IAM Users with Two Active Access Keys
- IAM Policies Attached to Roles or Groups Only
- IAM Users in Groups
- IAM Users have Hardware MFA Configured
- MFA for Users with Console Access
IAM Policies9
- No IAM Principals with access to blocked actions on KMS
- No IAM Principals with Full Administrator Permissions "*:*"
- No IAM Principals with Sensitive IAM Access
- No IAM Principals with Access to Invoke Any Lambda Function
- No IAM Principals with Unrestricted S3 Access
- No IAM Principals with Unrestricted S3 Read Access
- No IAM Principals with Access to Get All Secrets
- No IAM Principals with all service access or wildcard service access
- No IAM Principal with Unrestricted sts:AssumeRole Permissions
IAM Password Policy7
- IAM Password Policy Expires Passwords within 90 Days or less
- IAM Password Policy Requires Uppercase Characters
- IAM Password Policy Requires Lowercase Characters
- IAM Password Policy Requires Symbols
- IAM Password Policy Requires Numbers
- IAM Password Policy Requires Minimum Length of 14 Characters
- IAM Password Policy Configured to Prevent Password Reuse (24 or Greater)
IAM Roles4
- No IAM Principals with Unrestricted iam:PassRole Permissions
- Cross-Account IAM Roles use External IDs
- Check if Single Sign-On (SSO) is Used
- IAM Support Role is Created
IAM Root User4
- No Access Keys for Root Account
- Hardware MFA for Root Account is Enabled
- Root Account Not Used
- MFA for Root Account is Enabled
Cognito User Pools2
- Cognito user pool passwords should require min length 8, lower, upper, number, symbol, and temporary passwords <= 7 days
- MFA should be enabled for Cognito user pools
Access Analyzer Settings1
- IAM Access Analyzer is Enabled
Access Analyzer Findings1
- No Active Access Analyzer Findings
IAM CloudShell Access1
- Access to AWSCloudShellFullAccess Is Restricted
Resource Access Manager Shares1
- Resource Shares Shared Inside Organization Only
AppSync GraphQL APIs1
- AWS AppSync GraphQL APIs should not be authenticated with API keys
Cognito Identity Pools1
- Cognito identity pools should not allow unauthenticated identities
Bedrock AgentCore Gateways1
- Bedrock AgentCore Gateways should require authorization for inbound requests
CloudFormation Stacks1
- CloudFormation stacks should have associated service roles
Run these reports on your own cloud
Connect an account and get your first set of reports in minutes — free to start, no credit card required.
