← AWS Security Specialty: evidence-based security
06 / 8 · 35 MIN

Policies, tags, and access analysis

Protect authorization attributes and interpret findings precisely.

Concept and mechanism

A policy needs evaluation alongside other policies and principal type. Combining Deny with NotPrincipal in a resource policy can deny identities with a permissions boundary even when the exception appears suitable. Documentation recommends avoiding that combination and evaluating appropriate principal conditions such as aws:PrincipalArn. Adding an Allow does not remove an applicable explicit denial. Correcting the policy should preserve boundary intent rather than removing all controls to make a call succeed. Record action, resource, principal, conditions, and evidence before and after the change.

Guided application

ABAC depends on attribute integrity. If access is decided by Department and the user can freely change that tag, they can change the authorization criterion itself. Control permitted keys and values and confirm condition support for the specific action. Do not generalize ResourceTag to iam:PassRole: documentation warns of unreliable results with that approach. For sharing reviews, IAM Access Analyzer external-access findings identify potential policy access, not proof of actual reading. Activity logs answer a different question. Archiving a finding also does not revoke the bucket policy. Close a correction when actual access was changed and verified, keeping legitimate exceptions with ownership and rationale.

IN PRACTICE

The dashboard stopped showing an archived finding, but the policy retains the external principal. Access was not removed.

Common pitfalls

Allow as denial override; unprotected tag; universal ABAC; finding as activity; archiving as remediation.

Related topics: Keys, masking, and retention · Governance and central controls

Take this idea with you

Verify effective permission and control over attributes determining it.

Create account

Reference: Access Analyzer findings · SCS-C03