Resource shared outside the account
- Severity
- Low
- Service
- IAM Access Analyzer
- Check ID
- ACCESSANALYZER_EXTERNAL_ACCESS
What this check finds
IAM Access Analyzer found a resource that a principal outside this account can reach. This is a review item, not a defect — most entries are deliberate (a CI/CD role trusted by GitHub Actions, an SSO provider, a monitoring vendor's cross-account role). Confirm that each external principal listed is one you intended to grant access to, and that the actions it is granted are the minimum it needs. Only findings Access Analyzer still reports as ACTIVE are shown; ones you have already removed (RESOLVED) or suppressed with an archive rule (ARCHIVED) are excluded.
Passing looks like: No unreviewed external access to resources.
How to fix it
Review each resource against the external principal that can reach it. If the access is intended, record it — Access Analyzer archive rules suppress known-good sharing so real changes stand out: Console → IAM → Access Analyzer → Archive rules. If it is not intended, remove the external principal from the resource policy or role trust policy.
Compliance controls it is evidence for
A failing result counts against these controls in KloudLytics; a passing one is evidence towards them. How compliance mapping works
| Framework | Controls |
|---|---|
| HIPAA Security Rule |
|
| NIST SP 800-53 Rev5 (Moderate) |
|
| NIST Cybersecurity Framework 2.0 |
|
| ISO/IEC 27001:2022 Annex A |
|
Checked on every scan
KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs