All IAM users who belong to groups with the AdministratorAccess managed policy have multi-factor…
The AWS account root user has not been used within the last 24 hours. The root user has unrestricted…
AWS-managed IAM policies that grant full administrative access (: permissions) and are attached to users…
SAML (Security Assertion Markup Language) identity providers exist in your AWS account. SAML providers…
Customer-managed IAM policies that grant full administrative access through wildcard permissions (Action…
Unattached customer-managed IAM policies that grant unrestricted administrative access using : wildcards…
No IAM groups in your AWS account have the AdministratorAccess managed policy attached. Groups with this…
IAM inline policies that contain permission combinations enabling privilege escalation. Privilege…
IAM inline policies attached to users, roles, or groups do not grant unrestricted administrative access by…
IAM inline policies that grant unrestricted access to AWS CloudTrail using the cloudtrail: wildcard…
IAM inline policies that grant unrestricted access to AWS Key Management Service (KMS) using the wildcard…
Custom IAM policies that grant overly broad sts:AssumeRole permissions. Specifically, it flags policies…
Expired TLS/SSL server certificates stored in AWS IAM. Server certificates are used by services like…
Your AWS root user does not have any active access keys. The root user is the most privileged identity in…
Your AWS account's IAM password policy enforces password expiration within 90 days or less. Regular…
Your AWS account's password policy requires at least one lowercase letter (a-z) in user passwords. Strong…
Your AWS account's IAM password policy requires passwords to be at least 14 characters long. Longer…
Your AWS account's IAM password policy requires users to include at least one numeric character (0-9) in…
Your AWS account's password policy prevents IAM users from reusing any of their last 24 passwords…
Your AWS account's password policy requires at least one special character (symbol) in IAM user passwords…
Your AWS account's password policy requires at least one uppercase letter (A-Z) in IAM user passwords…
Customer-managed IAM policies that contain permissions enabling privilege escalation. Privilege escalation…
IAM users do not have policies attached directly to them. Instead, permissions should be assigned through…
IAM users, groups, and roles that have the AWS managed policy AWSCloudShellFullAccess attached. AWS…
Customer-managed IAM policies that grant unrestricted CloudTrail permissions using the cloudtrail…
Custom IAM policies that grant full access to AWS Key Management Service (KMS) using the kms: action…
IAM roles that have the AWS-managed AdministratorAccess policy attached. This policy grants unrestricted…
IAM roles that have the AWS-managed ReadOnlyAccess policy attached and allow external AWS accounts (or…
IAM service roles have trust policies that prevent the "confused deputy" attack. A confused deputy attack…
AWS Organizations has enabled centralized management of root user credentials across member accounts. When…
Your AWS root user account has hardware-based multi-factor authentication (MFA) enabled, rather than a…
Your AWS root account has multi-factor authentication (MFA) enabled. MFA adds an extra layer of security…
IAM users with active access keys that have not been rotated in over 90 days. Access keys are long-term…
At least one IAM role in your AWS account has the AWS managed SecurityAudit policy attached. The…
Your AWS account has at least one IAM role with the AWSSupportAccess managed policy attached. This…
IAM user access keys that have not been used for more than 45 days. Access keys are long-lived credentials…
IAM users that have the AdministratorAccess managed policy directly attached. The AdministratorAccess…
IAM users who have console access (password login) but have not used it within a configured inactivity…
IAM users have hardware-based multi-factor authentication (MFA) enabled. Hardware MFA devices include…
IAM users who can sign into the AWS Management Console have multi-factor authentication (MFA) enabled. MFA…
IAM users who have active access keys that have never been used. When an IAM user has console access and…
IAM users who have two active access keys at the same time. AWS allows each user to have up to two access…
IAM users who rely on long-lived access keys (static credentials) instead of temporary, role-based…