Resource shared outside the account

Severity
Low
Service
IAM Access Analyzer
Check ID
ACCESSANALYZER_EXTERNAL_ACCESS

What this check finds

IAM Access Analyzer found a resource that a principal outside this account can reach. This is a review item, not a defect — most entries are deliberate (a CI/CD role trusted by GitHub Actions, an SSO provider, a monitoring vendor's cross-account role). Confirm that each external principal listed is one you intended to grant access to, and that the actions it is granted are the minimum it needs. Only findings Access Analyzer still reports as ACTIVE are shown; ones you have already removed (RESOLVED) or suppressed with an archive rule (ARCHIVED) are excluded.

Passing looks like: No unreviewed external access to resources.

How to fix it

Review each resource against the external principal that can reach it. If the access is intended, record it — Access Analyzer archive rules suppress known-good sharing so real changes stand out: Console → IAM → Access Analyzer → Archive rules. If it is not intended, remove the external principal from the resource policy or role trust policy.

Compliance controls it is evidence for

A failing result counts against these controls in KloudLytics; a passing one is evidence towards them. How compliance mapping works

Compliance controls mapped to Resource shared outside the account
FrameworkControls
HIPAA Security Rule
  • 164.308(a)(4) Information Access Management
NIST SP 800-53 Rev5 (Moderate)
  • AC-3 Access Enforcement
  • AC-6 Least Privilege
NIST Cybersecurity Framework 2.0
  • PR.AA-05 Access permissions and authorizations are enforced with least privilege
ISO/IEC 27001:2022 Annex A
  • A.5.15 Access control
  • A.8.2 Privileged access rights
  • A.8.3 Information access restriction

Checked on every scan

KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs

More IAM Access Analyzer checks

All IAM Access Analyzer checks

Find out what is actually exposed in your AWS environment.

Connect one AWS account and run your first security assessment.

No credit card · Agentless · Read-only