1 Summary
What was read
2 The checks
3 What this could not check
Read from the policies you supplied, in your browser; nothing was sent to us. Account numbers and IDs are masked. Guidance, not an audit; see the terms.
Home › Free tools › Cloud permissions check
Drop in your cloud access policies: AWS IAM, Azure roles or Google Cloud IAM. It finds full administrator rights, grants that let someone make themselves administrator, anything open to the internet and trust that is too loose, then says what to fix first. Read in your browser.
No export to hand? See a sample:
1 Summary
2 The checks
3 What this could not check
Read from the policies you supplied, in your browser; nothing was sent to us. Account numbers and IDs are masked. Guidance, not an audit; see the terms.
One read-only command per cloud, run by someone with permission to view access settings. Or copy a single policy’s JSON from the console.
aws iam get-account-authorization-details --output json > iam.json in CloudShell. Read-only; needs iam:GetAccountAuthorizationDetails.az role definition list --custom-role-only true --output json > roles.json in Cloud Shell.gcloud projects get-iam-policy PROJECT_ID --format=json > iam.json in Cloud Shell.gcloud resource-manager folders get-iam-policy or gcloud organizations get-iam-policy.What happens to it: it is read in your browser and dropped once the report is drawn. Nothing is uploaded, account numbers are masked in the report, and our copy of your details carries only the cloud and the counts.
The questions people search for before they run the check.
Export the policies and look for full administrator grants, actions such as iam:PassRole, iam:CreatePolicyVersion or iam:Put*Policy on every resource, and Owner or Editor in Google Cloud. This check does that for AWS, Azure and Google Cloud exports, and says which grants to fix first.
A right that lets its holder give themselves more rights: creating or attaching a policy, changing who may assume a role, creating keys for another user, or acting as a more powerful service account. One of these on a small account makes it an administrator.
Run aws iam get-account-authorization-details --output json in CloudShell. It is read-only and lists every user, group, role, trust policy and your own managed policies. For Azure use az role definition list --custom-role-only true, and for Google Cloud gcloud projects get-iam-policy with --format=json.
Without a condition on the token's sub claim, the role trusts sign-ins from any GitHub repository, including one an attacker creates. Name your organisation, repository and branch in the condition.
No. It is read in your browser and dropped once the report is drawn, and account numbers are masked in the report. If you ask for the report, we keep your details and a one-line summary with the cloud and the counts.
Administrator rights for the few who need them, through roles with MFA; every other account limited to what it uses; and an alert the day someone grants too much.