AWS IAM Access Analyzer

Web · Android · iPhone · API · paid plans from $0.20/mo

Freedom report

Three barsScore 6.6

  • Free tierA free tier is on its own pricing page
  • Open codeNo open-source code on record
  • Runs widely3 of 6 device platforms
  • DocumentedPlans, terms and facts published

AWS IAM Access Analyzer helps teams review AWS permissions and move toward least privilege by identifying external, internal, and unused access. Its external analyzer monitors for new or changed permissions that allow public or cross-account access. Internal findings identify users and roles with access to S3, DynamoDB, or RDS, while unused-access analysis can flag roles, IAM user credentials, services, and actions. The service generates fine-grained IAM policies from access activity in AWS CloudTrail logs and validates policies with security warnings, errors, and best-practice suggestions. Custom policy checks can be added to CI/CD pipelines before deployment. Access Analyzer also provides last-accessed information for selected AWS services and actions, and integrates with AWS Security Hub CSPM and Amazon EventBridge. AWS says it uses automated reasoning to assess permissions. Policy validation, policy generation, and external access findings have no additional charge. Custom checks cost $0.0020 per API call; unused access analysis is $0.20 per IAM role or user per month, and internal analysis is $9.00 per resource monitored per Region per month.

Who it is for

The service suits security teams reviewing AWS permissions and compliance teams demonstrating access-control requirements. Developers can use custom policy checks in CI/CD pipelines before deployment.

What is good

  • Finds external, internal, and unused access
  • Generates policies from CloudTrail activity
  • Validates policies against IAM best practices
  • Integrates with Security Hub CSPM and EventBridge

What to know first

  • Custom checks cost $0.0020 per API call
  • Unused access analysis is $0.20 per role or user monthly
  • Internal analysis costs $9.00 per resource per Region monthly

Freedom251 review

AWS IAM Access Analyzer: the full review

AWS IAM Access Analyzer covers several permission-review tasks, with no additional charge for policy validation, policy generation, and external findings. Usage charges apply to custom checks and unused or internal access analysis.

Overview

AWS IAM Access Analyzer is an AWS permissions-analysis service for teams working toward least privilege. It is best suited to security and compliance teams managing AWS access; its mix of findings and policy tools is useful, but some analysis incurs usage charges.

Automated reasoning applies mathematical logic to assess permissions. The service can surface external, internal, and unused access, help refine policies, and support access-control audit requirements.

Key features

Access findings

External monitoring watches for new or changed permissions that grant public or cross-account access to AWS resources. Internal findings identify users and roles with access to S3, DynamoDB, or RDS. These views help teams focus reviews on exposure and access to selected business-critical resources, rather than treating all permissions as equivalent.

Unused access findings can identify unused roles, IAM user access keys and passwords, services, and actions. Last-accessed information for services and actions from select AWS services adds context for pruning permissions. These tools support least-privilege work, though the internal and unused analyzers carry ongoing charges.

Policy tools and workflow

Policy generation turns access activity captured in AWS CloudTrail logs into fine-grained IAM policies. Validation checks policies against IAM best practices and returns security errors, warnings, and suggestions. Custom policy checks can run in CI/CD pipelines before deployment, but each API call is billed.

Findings can feed analysis and notification workflows through AWS Security Hub CSPM and Amazon EventBridge. Policy simulation is supported. The service is SaaS for AWS, with Android, iOS, web, and API platforms listed; it is not a cross-cloud permissions analyzer.

Pricing

The free plan includes IAM policy validation, policy generation, and external access analysis at no additional charge. That makes it a practical starting point for teams wanting policy guidance and public or cross-account findings without analyzer usage fees.

  • IAM policy validation: 0.00 USD per free; provided at no additional charge.
  • Policy generation: 0.00 USD per free; provided at no additional charge.
  • External access analyzer: 0.00 USD per free; public and cross-account findings are provided at no additional charge.
  • Custom policy checks: 0.00 USD per month, billed at $0.0020 per API call. Costs depend on the number of checks run through the APIs, so frequent pipeline checks add usage charges.
  • Unused access analyzer: 0.20 USD per month, billed at $0.20 per IAM role or IAM user per month. One analyzer covers all Regions in a partition because roles and users are global; organizations with many roles or users should account for the per-identity cost.
  • Internal access analyzer: 9.00 USD per month, billed at $9.00 per resource monitored per Region per month. This is aimed at organizations monitoring business-critical resources, but costs rise with monitored resources and Regions.

The paid analysis options are usage-priced rather than a single flat subscription. No seat-based pricing or trial term is part of these plans.

Platforms

Access Analyzer is a SaaS service for AWS. Android, iOS, web, and API are listed as platforms, but its permissions analysis is specific to AWS resources.

Who it's for

Security teams reviewing and refining AWS access can use its exposure, internal-access, and unused-access findings to direct permission reviews. Compliance teams can use it to demonstrate access-control audit requirements. It is less suitable for organizations seeking a general identity-management product or analysis spanning multiple cloud providers.

Pros and cons

  • Pros: External findings, policy validation, and policy generation are provided at no additional charge, covering useful parts of an AWS permission-review workflow.
  • Pros: Internal and unused findings reach beyond public exposure, including selected resource types and dormant identities or permissions.
  • Pros: Custom checks can be placed in CI/CD workflows, helping teams review policies before deployment.
  • Cons: Internal and unused analysis is billed by monitored resource or identity, and custom checks are billed per API call.
  • Cons: The service focuses on AWS; it is not a fit for teams needing a general or cross-cloud access analyzer.

Alternatives

For a broader cloud-security comparison, browse Cloud Infrastructure Entitlement Management Software or Identity and Access Management Software. For sign-on-focused needs, see Single Sign-On Software.

  • C3M Cloud Control is worth considering for a free assessment of up to 2 cloud accounts; its main plan uses custom pricing, with a free trial also offered.
  • Qualys TotalCloud offers a free license with limited API calls for control evaluation, while its platform subscription has variable pricing.
  • Sysdig Secure may suit teams seeking a host-based licensing model for cloud security; licensing is based on environment hosts, including compute instances for CSPM.
  • FortiCNAPP offers Standard tiers with one- or three-year terms and entitlement per vCPU.
  • Palo Alto Networks Cortex Cloud API Security is another paid option for readers comparing API security software.
  • Veza SSPM is another paid option to consider.
  • Wiz Defend uses modular licensing with quote-based pricing and has no free plan.
  • Apono is another paid option to compare.

Verdict

AWS IAM Access Analyzer is a strong fit for AWS security and compliance teams that want no-additional-charge policy validation, policy generation, and external access findings in one permissions workflow. Look elsewhere if you need cross-cloud coverage, or budget carefully if internal and unused analysis or frequent custom checks are central to your use.

AWS IAM Access Analyzer plans and pricing

All plans
IAM policy validation Free Provided at no additional charge Validates policies against IAM best practices aws.amazon.com · 29 Sept 2026
Policy generation Free Provided at no additional charge Generates fine-grained policies based on access activity captured in logs aws.amazon.com · 29 Sept 2026
External access analyzer Free Provided at no additional charge Public and cross-account access findings for AWS resources aws.amazon.com · 29 Sept 2026
Custom policy checks Free $0.0020 per API call Charged based on the number of custom policy checks run through IAM Access Analyzer APIs aws.amazon.com · 29 Sept 2026
Unused access analyzer $0.20/mo $0.20 per IAM role or IAM user per month One analyzer across all Regions in a partition because IAM roles and users are global aws.amazon.com · 29 Sept 2026
Internal access analyzer $9/mo $9.00 per resource monitored per Region per month Monitors access to business-critical AWS resources within an AWS organization aws.amazon.com · 29 Sept 2026

Compared on identity and access management software

Supported clouds
AWS
Policy simulation
Yes
Deployment model
saas

Best AWS IAM Access Analyzer alternatives

See all 12