Evaluating public and cross account access at scale with IAM Access Analyzer for Amazon S3
Storage Blog
This article discusses how to use the IAM Access Analyzer for Amazon S3 to evaluate and remediate public and cross-account access to S3 buckets at scale.
Specifically, the article covers:
- How to set up an IAM Access Analyzer for S3 in a given AWS region
- Viewing findings related to public and cross-account access to S3 buckets
- Reviewing and remediating findings for public buckets by blocking public access or archiving if needed
- Reviewing and remediating findings for cross-account access by editing bucket policies or ACLs
- Additional considerations like using Access Analyzer across regions, object-level access, and expanded Access Analyzer capabilities
- Conclusion highlighting how Access Analyzer helps audit and refine S3 access permissions at scale
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Jun 11
2024
2024
AWS IAM Access Analyzer now offers policy checks for public and critical resource access
May 14
2024
2024
Governing and securing AWS PrivateLink service access at scale in multi-account environments
Jun 11
2024
2024
AWS IAM Access Analyzer now offers recommendations to refine unused access
Jun 17
2025
2025
IAM Access Analyzer now identifies who in your AWS organization can access your AWS resources
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.