AWS SAA – Lecture 27: IAM Security Tools

Published on
Written by Henry Nguyen

Phase Verbs / Action Phrases

PhraseMeaning
generate (a report)create an output file/document from AWS
audit (credentials/permissions)review and verify security-related settings
reduce (permissions)remove unnecessary access rights
grant (service permissions)allow a user to access a service

Technical Vocabulary

TermDefinition
IAM Credentials ReportAccount-level CSV report of all IAM users and the status of their credentials (passwords, access keys, MFA)
IAM Access AdvisorUser-level tool showing which AWS services a user has been granted access to and when they last used each
Least privilege principleGive users only the minimum permissions needed to do their job
Service permissionsWhat AWS services a user is allowed to call (as defined by their policies)

Key Concepts

Two IAM Security Tools

ToolScopeWhat It Shows
Credentials ReportAccount-levelAll users + status of password, access keys, MFA
Access AdvisorUser-levelService permissions granted + when last used

IAM Credentials Report

  • Generated from the IAM console → download as CSV
  • Shows for every user: password enabled/rotated, access keys active/rotated, MFA enabled
  • Useful for auditing who has credentials and whether they’re following security best practices

IAM Access Advisor

  • Per-user view inside IAM
  • Helps identify unused permissions → remove them to follow least privilege
  • Shows: service name, granted permission, last access time

Why Use These Tools?

  • Enforce least privilege: if a user hasn’t accessed S3 in 90 days, they probably don’t need S3 access
  • Quickly spot users with no MFA, old access keys, or excessive permissions

Exam Tips

  • Credentials Report = account-level audit tool
  • Access Advisor = user-level audit tool
  • Both support the principle of least privilege
  • These are audit/monitoring tools — they don’t change permissions themselves