Tech riderRev. 29 Sept 2026
  1. 1Runs onAndroid, API, iOS, Web
  2. 2CostsFree plan · paid from $0.20/mo
  3. 3Supported cloudsAWS
  4. 4Policy simulationYes
  5. 5Deployment modelsaas
5 lines stated Written from the maker's own pages: aws.amazon.com

Overview

AWS IAM Access Analyzer helps teams set, verify, and refine permissions toward least privilege. It examines external, internal, and unused access to AWS resources. External analysis monitors for new or changed permissions that allow public or cross-account access; internal findings identify users and roles with access to S3, DynamoDB, or RDS resources. Unused-access findings can identify unused roles, IAM user keys and passwords, services, and actions. The service can generate fine-grained IAM policies from activity captured in AWS CloudTrail logs, and policy validation supplies security warnings, errors, general warnings, and best-practice suggestions. Custom policy checks can be integrated into CI/CD pipelines before deployment. The analyzer also provides last-accessed information for services and actions from select AWS services and connects with AWS Security Hub CSPM and Amazon EventBridge for findings workflows. AWS says automated reasoning technology applies mathematical logic to assess permissions. Policy validation, policy generation, and external access analysis are provided at no additional charge. Other listed charges include $0.0020 per custom policy-check API call, $0.20 per IAM role or user per month for unused-access analysis, and $9.00 per resource monitored per Region per month for internal access analysis.

Who it is for

The analyzer suits AWS security teams reviewing permissions and compliance teams demonstrating access-control audit requirements. It also fits development teams that want policy checks in CI/CD pipelines.

What is good

  • Analyzes external, internal, and unused access
  • Generates IAM policies from CloudTrail activity
  • Policy validation provides warnings and best-practice suggestions
  • Custom checks can run in CI/CD pipelines
  • Policy validation, generation, and external analysis cost nothing extra

What to know first

  • Custom checks cost $0.0020 per API call
  • Unused-access analysis costs $0.20 per role or user monthly
  • Internal analysis costs $9.00 per resource per Region monthly

Specifiction review

AWS IAM Access Analyzer: the full review

IAM Access Analyzer covers several kinds of access review and policy work for AWS resources, with policy validation, generation, and external analysis at no additional charge. Custom checks and unused or internal access analysis carry listed usage-based charges.

Overview

AWS IAM Access Analyzer is an AWS permissions analysis service for teams working to reduce access to least privilege. It suits security teams reviewing AWS access and compliance teams demonstrating access-control requirements. Its broad set of AWS-focused checks and policy tools are useful, though some analysis incurs usage-based charges.

Key features

Findings across resource access

The service continuously checks for new or changed resource permissions that expose AWS resources publicly or across accounts. Internal findings identify users and roles with access to S3, DynamoDB, or RDS; unused-access findings can surface dormant roles, IAM user keys or passwords, services, and actions. Last-accessed data for services and actions from select AWS services adds context to review decisions.

This range helps teams investigate both exposure and stale permissions, but internal analysis is limited to the named resource types. Internal and unused analysis also have separate usage charges, so organizations should consider the monitored resources and identities before enabling them broadly.

Policy work and integrations

Access activity captured in CloudTrail logs can be turned into fine-grained IAM policies. Validation checks policies for security warnings, errors, general warnings, and best-practice suggestions. Custom policy checks can run in CI/CD pipelines before deployment, while Security Hub CSPM and EventBridge support findings analysis and notification workflows.

Automated reasoning applies mathematical logic to assess AWS permissions. That gives the service a formal basis for evaluating permissions, but it remains centered on AWS policy and resource access rather than general-purpose identity management.

Pricing

The core capabilities have no additional charge: IAM policy validation, policy generation, and external access analysis are each 0.00 USD per free. That makes policy review and public or cross-account exposure monitoring a straightforward fit for AWS teams seeking a no-charge starting point.

Custom policy checks are 0.00 USD per month, billed at $0.0020 per API call. This suits teams that need pipeline checks, but costs rise with each check run. The unused access analyzer is 0.20 USD per month, billed at $0.20 per IAM role or IAM user per month; one analyzer covers all Regions in a partition because roles and users are global. The internal access analyzer is 9.00 USD per month, billed at $9.00 per resource monitored per Region per month, for teams monitoring business-critical resources within an AWS organization. These charges make targeted use more compelling than indiscriminate monitoring.

Platforms

Access Analyzer is a SaaS service for AWS, with web and API platforms plus Android and iOS listed. Policy simulation is supported. Identity-related capabilities include SAML 2.0, OAuth 2.0, and OIDC, FIDO2 authenticators, virtual authenticator apps, and RADIUS MFA, as well as directory sync and lifecycle provisioning. Adaptive access and adaptive access policies are not supported.

Who it's for

Choose Access Analyzer if your organization operates AWS resources and needs to review exposure, stale access, or policy quality. Its findings and policy generation are particularly relevant to security teams refining permissions; compliance teams can use it to demonstrate access-control audit requirements. It is less suitable as a standalone choice for organizations seeking broad identity management or adaptive access controls.

Pros and cons

  • Pros: External access analysis, policy validation, and policy generation carry no additional charge, giving AWS teams several useful permission controls without a per-resource fee.
  • Pros: Findings cover external, selected internal, and unused access, while integrations can route findings into existing analysis and notification workflows.
  • Cons: Internal analysis is limited to S3, DynamoDB, and RDS resources, and costs $9.00 per resource monitored per Region per month.
  • Cons: Custom checks and unused-access analysis add usage-based costs, and adaptive access is not supported.

Alternatives

For broader cloud-security options, consider these alternatives:

  • CrowdStrike Falcon Surface may suit readers seeking a paid product with a free trial and Linux, macOS, web, and Windows platforms; its Falcon Exposure Management plan requires scheduling a demo.
  • C3M Cloud Control offers a free cloud security assessment for up to 2 cloud accounts and a free trial, making it worth considering for a small initial assessment.
  • Qualys TotalCloud has a free license with limited API calls for control evaluation and a free trial, which may fit a limited evaluation before a paid subscription.
  • Rapid7 Surface Command is another paid option with a free trial and API, desktop, and web platforms.
  • SentinelOne Singularity Cloud Security is a paid option for readers who want Android, iOS, web, and API platforms; its listed plans are billed per endpoint.
  • Sysdig Secure bases licensing on the number of hosts in a customer's environment, including compute instances for CSPM.
  • FortiCNAPP offers Standard plans with one- or three-year terms and entitlement per vCPU.
  • Palo Alto Networks Cortex Cloud API Security is another alternative.

Readers comparing broader categories can also browse Cloud Infrastructure Entitlement Management Software, Identity and Access Management Software, and Single Sign-On Software.

Verdict

AWS IAM Access Analyzer is a strong fit for AWS organizations that want to inspect permissions and improve policies, especially when external findings and validation are the priorities. Choose it for its AWS-specific access coverage and no-additional-charge policy tools; look elsewhere if you need adaptive access, broader identity management, or cannot accommodate usage-based charges for deeper analysis.

AWS IAM Access Analyzer plans and pricing

All plans
IAM policy validation Free Provided at no additional charge Validates policies against IAM best practices aws.amazon.com · 29 Sept 2026
Policy generation Free Provided at no additional charge Generates fine-grained policies based on access activity captured in logs aws.amazon.com · 29 Sept 2026
External access analyzer Free Provided at no additional charge Public and cross-account access findings for AWS resources aws.amazon.com · 29 Sept 2026
Custom policy checks Free $0.0020 per API call Charged based on the number of custom policy checks run through IAM Access Analyzer APIs aws.amazon.com · 29 Sept 2026
Unused access analyzer $0.20/mo $0.20 per IAM role or IAM user per month One analyzer across all Regions in a partition because IAM roles and users are global aws.amazon.com · 29 Sept 2026
Internal access analyzer $9/mo $9.00 per resource monitored per Region per month Monitors access to business-critical AWS resources within an AWS organization aws.amazon.com · 29 Sept 2026

Compared on identity and access management software

Supported clouds
AWSaws.amazon.com
Policy simulation
Yesaws.amazon.com
Deployment model
saasaws.amazon.com

Facts

Purpose
IAM Access Analyzer helps set, verify, and refine permissions on the journey toward least privilege.aws.amazon.com · 29 Sept 2026
Access findings
It analyzes external, internal, and unused access to AWS resources.aws.amazon.com · 29 Sept 2026
Policy generation
It generates fine-grained IAM policies from access activity captured in AWS CloudTrail logs.aws.amazon.com · 29 Sept 2026
Policy validation
Policy validation provides security warnings, errors, general warnings, and IAM best practice suggestions.aws.amazon.com · 29 Sept 2026
External monitoring
The external access analyzer continuously monitors for new or updated resource permissions that grant public or cross-account access.aws.amazon.com · 29 Sept 2026
Internal resource coverage
Internal access findings identify users and roles with access to S3, DynamoDB, or RDS resources.aws.amazon.com · 29 Sept 2026
Unused access
Unused access findings can identify unused roles, IAM user access keys, IAM user passwords, services, and actions.aws.amazon.com · 29 Sept 2026
Last accessed data
The service provides last accessed information for AWS services and actions from select AWS services.aws.amazon.com · 29 Sept 2026
Integrations
It integrates with AWS Security Hub CSPM and Amazon EventBridge for findings analysis and notification workflows.aws.amazon.com · 29 Sept 2026
Development workflow
Custom policy checks can be integrated into CI/CD pipelines to review policies before deployment.aws.amazon.com · 29 Sept 2026
Security method
The service uses automated reasoning technology, applying mathematical logic to assess AWS permissions.aws.amazon.com · 29 Sept 2026
Intended users
AWS describes the service as helping security teams review and refine access and compliance teams demonstrate access-control audit requirements.aws.amazon.com · 29 Sept 2026

Best AWS IAM Access Analyzer alternatives

See all 20

Where it ranks on Specifiction

Is AWS IAM Access Analyzer yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources