AWS IAM
LiveIdentity & AccessAWS IAM connector — read-only, agentless
Scans AWS IAM users, roles, groups, and policies to map effective permissions and find over-privileged or stale principals.
What we scan
- IAM users, roles, groups, and attached/inline policies (never resource data)
- Effective permission relationships for blast-radius analysis
Read-only monitoring — nothing in your AWS IAM data changes unless you turn on auto-remediation and grant write access separately.
Security findings
13 detection rules run on every AWS IAM scan. Each finding ships with a plain-language explanation, the evidence behind it and remediation steps.
- CRITICALMisconfig
AWS account root user has MFA disabled
- CRITICALMisconfig
AWS account root user has active access keys
- CRITICALPublic exposure
IAM role trust policy allows any principal to assume it
- HIGHMisconfig
IAM console user has no MFA device
- HIGHOver permission
IAM user holds a wildcard (Action:* Resource:*) policy
- HIGHOver permission
IAM user has AdministratorAccess attached
- MEDIUMStale access
IAM access key has not been rotated in over 90 days
- MEDIUMMisconfig
Account password policy allows short passwords
- LOWStale access
IAM console user has been inactive for over 90 days
- LOWMisconfig
Account password policy does not expire passwords
- LOWMisconfig
Account password policy allows password reuse
- LOWMisconfig
IAM user has an inline policy
- LOWMisconfig
IAM group has no members
How to connect AWS IAM
Step 1
Sign up or log in to 8200.dev
Step 2
Go to Connectors → AWS IAM
Step 3
Click Connect and authorize via AWS IAM's consent screen
Step 4
8200.dev scans automatically — results appear within minutes
Connect your first source in minutes — free, read-only, no sales call.