Reports for Every Cloud

Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.

58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results
ASecureCloud report preview
AWS logo

Identity & Access Management Best Practices

53 controls
15 services covered

Covers least-privilege controls across IAM, IAM Identity Center, IAM Access Analyzer, Cognito, AppSync authorization, Resource Access Manager sharing, Bedrock AgentCore, and CloudFormation service roles — including passwords, MFA, access keys, and high-risk permissions.

What we check

IAM Identity Center Permission Sets10
  • No SSO Permission Set with access to blocked actions on KMS
  • No SSO Permission Set with Full Administrator Permissions "*:*"
  • No SSO Permission Set with Unrestricted iam:PassRole Permissions
  • No SSO Permission Set with Sensitive IAM Access
  • No SSO Permission Set with Access to Invoke Any Lambda Function
  • No SSO Permission Set with Unrestricted S3 Access
  • No SSO Permission Set with Unrestricted S3 Read Access
  • No SSO Permission Set with Access to Get All Secrets
  • No SSO Permission Set with all service access or wildcard service access
  • No SSO Permission Set with Unrestricted sts:AssumeRole Permissions
IAM Users and Access Keys9
  • IAM Access Keys Are Rotated every 90 Days
  • No Inline IAM Policies Attached
  • Do Not Create Access Keys During Initial Setup for IAM Users with Console Password
  • No IAM Users with Administrator Privileges without MFA
  • No IAM Users with Two Active Access Keys
  • IAM Policies Attached to Roles or Groups Only
  • IAM Users in Groups
  • IAM Users have Hardware MFA Configured
  • MFA for Users with Console Access
IAM Policies9
  • No IAM Principals with access to blocked actions on KMS
  • No IAM Principals with Full Administrator Permissions "*:*"
  • No IAM Principals with Sensitive IAM Access
  • No IAM Principals with Access to Invoke Any Lambda Function
  • No IAM Principals with Unrestricted S3 Access
  • No IAM Principals with Unrestricted S3 Read Access
  • No IAM Principals with Access to Get All Secrets
  • No IAM Principals with all service access or wildcard service access
  • No IAM Principal with Unrestricted sts:AssumeRole Permissions
IAM Password Policy7
  • IAM Password Policy Expires Passwords within 90 Days or less
  • IAM Password Policy Requires Uppercase Characters
  • IAM Password Policy Requires Lowercase Characters
  • IAM Password Policy Requires Symbols
  • IAM Password Policy Requires Numbers
  • IAM Password Policy Requires Minimum Length of 14 Characters
  • IAM Password Policy Configured to Prevent Password Reuse (24 or Greater)
IAM Roles4
  • No IAM Principals with Unrestricted iam:PassRole Permissions
  • Cross-Account IAM Roles use External IDs
  • Check if Single Sign-On (SSO) is Used
  • IAM Support Role is Created
IAM Root User4
  • No Access Keys for Root Account
  • Hardware MFA for Root Account is Enabled
  • Root Account Not Used
  • MFA for Root Account is Enabled
Cognito User Pools2
  • Cognito user pool passwords should require min length 8, lower, upper, number, symbol, and temporary passwords <= 7 days
  • MFA should be enabled for Cognito user pools
Access Analyzer Settings1
  • IAM Access Analyzer is Enabled
Access Analyzer Findings1
  • No Active Access Analyzer Findings
IAM CloudShell Access1
  • Access to AWSCloudShellFullAccess Is Restricted
Resource Access Manager Shares1
  • Resource Shares Shared Inside Organization Only
AppSync GraphQL APIs1
  • AWS AppSync GraphQL APIs should not be authenticated with API keys
Cognito Identity Pools1
  • Cognito identity pools should not allow unauthenticated identities
Bedrock AgentCore Gateways1
  • Bedrock AgentCore Gateways should require authorization for inbound requests
CloudFormation Stacks1
  • CloudFormation stacks should have associated service roles

Run these reports on your own cloud

Connect an account and get your first set of reports in minutes — free to start, no credit card required.