Skip to main content

AWS (Amazon Web Services)

Description​

The AWS connector uses the AWS IAM REST API to discover IAM users, groups, roles, group memberships, and the account root user within an AWS account. It uses AWS Signature Version 4 (SigV4) request signing to authenticate directly with the IAM service without requiring any AWS SDK installation on the OrbisID server.

System Type Classification​

FieldValue
System TypeInfrastructure
Default Scan Priority500

Version Support​

OrbisID EditionSupported
CommunityNo
ProYes
EnterpriseYes

AWS scanning requires a Pro or Enterprise licence.

Supported Protocol​

ProtocolPortNotes
AWS IAM REST API (HTTPS + SigV4)443 TCPGlobal IAM endpoint: iam.amazonaws.com

What OrbisID Discovers​

DataSource
IAM usersListUsers (paginated via Marker)
Console access per userGetLoginProfile per user — whether a console login profile (password) exists, distinct from programmatic-only access via access keys
IAM groupsListGroups (paginated via Marker)
IAM rolesListRoles (paginated via Marker)
Group membershipsGetGroup per group
Attached managed policiesListAttachedUserPolicies / ListAttachedRolePolicies / ListAttachedGroupPolicies per user/role/group
Account root userRead from the <root_account> row of AWS's own IAM credential report (GenerateCredentialReport / GetCredentialReport) — the root user has no IAM principal of its own, so it is never returned by ListUsers. Its ARN and MFA/access-key/password risk attributes all come directly from that row; OrbisID does not assemble any part of its identity itself, and only adds it if AWS's own API actually returns the row
AWS Organizations FMS delegated administratorsfms:ListAdminAccountsForOrganization — member accounts within the organization granted org-wide administrative rights over Firewall Manager
User status (active/inactive)Derived from access key and login profile existence

Roles are discovered as accounts alongside users — AWS roles are non-human, assumed-by-entities accounts rather than something assigned to a user directly, and are relevant to PAM reconciliation for service accounts that use role-based access.

The credential report is AWS's own standard mechanism for exposing root user state (it's what CIS AWS Foundations Benchmark tooling uses) — report generation is asynchronous, so OrbisID triggers it and polls for up to 60 seconds until it's ready.

Firewall Manager delegated administrator accounts are each represented as an account (named by their 12-digit AWS account ID) linked to a shared, always-privileged "AWS Organizations FMS Delegated Administrator" entitlement. This step only returns data when OrbisID is scanning with credentials from the organization's management account (or an account already set up as an FMS admin) — for every other AWS account it will fail with an access-denied error, which is expected, logged, and does not fail the rest of the scan.

Privileged Classification​

Each attached managed policy becomes an entitlement (AWS_IAM_POLICY). A user, role, or group is flagged privileged if it has one of the following AWS managed policies attached directly:

AdministratorAccess, PowerUserAccess, IAMFullAccess, SecurityAudit, AWSSecurityHubFullAccess, AWSOrganizationsFullAccess, AWSDirectoryServiceFullAccess, AWSAccountManagementFullAccess

A user or role also inherits privileged status from any group it belongs to that has one of these policies attached — this is AWS's standard admin pattern (attach AdministratorAccess to an "Administrators" group and add users to it, rather than attaching it to each user directly), so group-granted privilege is rolled up to members, not just recorded against the group itself.

The account root user is always flagged privileged, since it has permanent, unrestricted access to every resource plus billing and account closure that cannot be limited by any policy.

Any IAM user with a console login profile is always flagged privileged, regardless of what IAM permissions it holds — a password grants standing, interactive human access to the AWS Management Console, which is a distinct risk surface from API-only access via access keys and is tracked as its own "AWS Console Access" entitlement.

Known Limitation

Only AWS managed policies attached directly to a user/role/group are evaluated against the privileged list above. Inline policies (embedded directly on a user, role, or group) and the permission content of customer-managed policies are not currently parsed, so privilege granted exclusively through those mechanisms will not be flagged.

Connection Requirements​

AWS IAM User (Scanning Identity)​

OrbisID authenticates using an IAM user with an access key. The IAM user should be a dedicated service account for OrbisID with read-only IAM permissions.

Recommended IAM policy:

{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "OrbisIDIAMReadOnly",
"Effect": "Allow",
"Action": [
"iam:ListUsers",
"iam:GetLoginProfile",
"iam:ListGroups",
"iam:ListRoles",
"iam:GetGroup",
"iam:ListAttachedUserPolicies",
"iam:ListAttachedRolePolicies",
"iam:ListAttachedGroupPolicies",
"iam:GetUser",
"iam:GenerateCredentialReport",
"iam:GetCredentialReport"
],
"Resource": "*"
}
]
}

Attach this policy to the dedicated IAM user and generate an Access Key ID and Secret Access Key.

Optional: Organizations FMS Delegated Administrators

If this system's credentials belong to the AWS Organizations management account (or an existing Firewall Manager admin), also add "fms:ListAdminAccountsForOrganization" to the statement above to additionally discover delegated FMS administrator accounts. This is optional — every other account will simply skip this step with a logged warning rather than fail the scan.

Credential Mapping​

OrbisID FieldAWS Value
credential.usernameIAM Access Key ID (e.g., AKIAIOSFODNN7EXAMPLE)
credential.passwordIAM Secret Access Key

System Attributes​

AttributeRequiredDefaultDescription
awsRegionNous-east-1AWS region for the IAM endpoint (IAM is global, but region is used for SigV4 signing)
awsAccountIdNo—AWS account ID (12-digit) — stored for reference in scan results

Network Requirements​

RequirementDetail
Outbound HTTPSOrbisID server (or On-Premise Agent) must reach iam.amazonaws.com on port 443

Configuration Steps​

  1. Create a dedicated IAM user (e.g., orbisid-scanner) in the AWS account
  2. Attach the recommended IAM read-only policy
  3. Generate an Access Key for the IAM user — note the Access Key ID and Secret Access Key
  4. Create a Credential in OrbisID:
    • Username: Access Key ID
    • Password: Secret Access Key
  5. Navigate to Systems → Add System
  6. Fill in the fields:
FieldValue
NameDescriptive name (e.g., AWS – Production Account)
Hostname / IP Addressiam.amazonaws.com — pre-filled and locked; AWS IAM is a fixed global endpoint, not something you configure per system
OS TypeAWS
System TypeInfrastructure
CredentialThe IAM user credential created above
  1. Optionally, in the Connection Attributes section, set AWS Account ID (awsAccountId) for reference
  2. Click Test Connection — this calls iam:GetUser with the configured access key to confirm the credential actually authenticates, not just that the network path is reachable
  3. Click Save
Multiple AWS Accounts

To scan multiple AWS accounts, add a separate OrbisID target system for each account with its own dedicated IAM user and access key.

Access Key Security

Store the IAM Secret Access Key only in OrbisID's encrypted credential store. Do not share it across systems. Rotate access keys regularly and use a dedicated scanning-only IAM user with minimal permissions.

Real-Time Account & Entitlement Events​

Beyond periodic full scans, OrbisID can drain an SQS queue (fed by CloudTrail via an EventBridge rule you configure) to detect IAM user create/delete and policy/group membership changes near-real-time. See Real-Time Events — Pro/Enterprise only. IAM has no clean "disable a user" concept, so account-enable/disable events aren't detected this way.

Troubleshooting​

SymptomLikely CauseResolution
InvalidClientTokenIdAccess Key ID is invalid or deletedVerify the access key exists and is active in the AWS console
SignatureDoesNotMatchSecret Access Key is incorrectRegenerate or verify the secret access key
AccessDeniedMissing IAM permissionsAttach the recommended policy; verify iam:ListUsers, iam:GetLoginProfile, iam:ListGroups, iam:ListRoles, iam:GetGroup, iam:ListAttachedGroupPolicies, iam:GetUser, iam:GenerateCredentialReport, iam:GetCredentialReport are allowed
No IAM users show console access, even ones you know have a passwordMissing iam:GetLoginProfile permissionConsole access is left undetermined (not assumed false) when this call is denied — check the scan's log viewer for a per-user warning, then attach iam:GetLoginProfile
Account root user missing from scan resultsCredential report generation/retrieval failed or timed outCheck the scan's log viewer for the specific error (e.g. missing iam:GenerateCredentialReport/iam:GetCredentialReport permission); a very large account can occasionally take longer than OrbisID's 60-second poll window to generate a report for the first time — a subsequent scan will succeed once AWS has cached the report
No AWS Organizations FMS delegated administrator accounts discoveredExpected in almost all casesThis step only succeeds when scanning with credentials from the AWS Organizations management account (or an existing FMS admin) — an access-denied warning in the scan log for every other account is normal, not an error to fix
Connection refused / timeoutNetwork path to iam.amazonaws.com blockedCheck outbound firewall rules on port 443 from the OrbisID server or agent
No groups or users returnedAccount has no IAM entitiesVerify the correct AWS account is being scanned; check the access key belongs to the intended account
certificate_unknown / "No subject alternative DNS name matching iam.amazonaws.com found"A TLS-inspecting proxy, firewall, or VPN on the network path between the OrbisID server (or agent) and AWS is intercepting the connection and presenting its own certificate instead of Amazon'sConfirm what certificate is actually being served: openssl s_client -connect iam.amazonaws.com:443 -servername iam.amazonaws.com | openssl x509 -noout -subject -issuer -ext subjectAltName from the exact host/container running the scan. If the issuer isn't Amazon, work with network/security teams to exempt iam.amazonaws.com from TLS inspection, or route the scan through an On-Premise Agent on a network with a clean egress path