AWS (Amazon Web Services)
Description
The AWS connector uses the AWS IAM REST API to discover IAM users, groups, roles, group memberships, and the account root user within an AWS account. It uses AWS Signature Version 4 (SigV4) request signing to authenticate directly with the IAM service without requiring any AWS SDK installation on the OrbisID server.
System Type Classification
| Field | Value |
|---|---|
| System Type | Infrastructure |
| Default Scan Priority | 500 |
Version Support
| OrbisID Edition | Supported |
|---|---|
| Community | No |
| Pro | Yes |
| Enterprise | Yes |
AWS scanning requires a Pro or Enterprise licence.
Supported Protocol
| Protocol | Port | Notes |
|---|---|---|
| AWS IAM REST API (HTTPS + SigV4) | 443 TCP | Global IAM endpoint: iam.amazonaws.com |
What OrbisID Discovers
| Data | Source |
|---|---|
| IAM users | ListUsers (paginated via Marker) |
| Console access per user | GetLoginProfile per user — whether a console login profile (password) exists, distinct from programmatic-only access via access keys |
| IAM groups | ListGroups (paginated via Marker) |
| IAM roles | ListRoles (paginated via Marker) |
| Group memberships | GetGroup per group |
| Attached managed policies | ListAttachedUserPolicies / ListAttachedRolePolicies / ListAttachedGroupPolicies per user/role/group |
| Account root user | Read from the <root_account> row of AWS's own IAM credential report (GenerateCredentialReport / GetCredentialReport) — the root user has no IAM principal of its own, so it is never returned by ListUsers. Its ARN and MFA/access-key/password risk attributes all come directly from that row; OrbisID does not assemble any part of its identity itself, and only adds it if AWS's own API actually returns the row |
| AWS Organizations FMS delegated administrators | fms:ListAdminAccountsForOrganization — member accounts within the organization granted org-wide administrative rights over Firewall Manager |
| User status (active/inactive) | Derived from access key and login profile existence |
Roles are discovered as accounts alongside users — AWS roles are non-human, assumed-by-entities accounts rather than something assigned to a user directly, and are relevant to PAM reconciliation for service accounts that use role-based access.
The credential report is AWS's own standard mechanism for exposing root user state (it's what CIS AWS Foundations Benchmark tooling uses) — report generation is asynchronous, so OrbisID triggers it and polls for up to 60 seconds until it's ready.
Firewall Manager delegated administrator accounts are each represented as an account (named by their 12-digit AWS account ID) linked to a shared, always-privileged "AWS Organizations FMS Delegated Administrator" entitlement. This step only returns data when OrbisID is scanning with credentials from the organization's management account (or an account already set up as an FMS admin) — for every other AWS account it will fail with an access-denied error, which is expected, logged, and does not fail the rest of the scan.
Privileged Classification
Each attached managed policy becomes an entitlement (AWS_IAM_POLICY). A user, role, or group is flagged privileged if it has one of the following AWS managed policies attached directly:
AdministratorAccess, PowerUserAccess, IAMFullAccess, SecurityAudit, AWSSecurityHubFullAccess, AWSOrganizationsFullAccess, AWSDirectoryServiceFullAccess, AWSAccountManagementFullAccess
A user or role also inherits privileged status from any group it belongs to that has one of these policies attached — this is AWS's standard admin pattern (attach AdministratorAccess to an "Administrators" group and add users to it, rather than attaching it to each user directly), so group-granted privilege is rolled up to members, not just recorded against the group itself.
The account root user is always flagged privileged, since it has permanent, unrestricted access to every resource plus billing and account closure that cannot be limited by any policy.
Any IAM user with a console login profile is always flagged privileged, regardless of what IAM permissions it holds — a password grants standing, interactive human access to the AWS Management Console, which is a distinct risk surface from API-only access via access keys and is tracked as its own "AWS Console Access" entitlement.
Only AWS managed policies attached directly to a user/role/group are evaluated against the privileged list above. Inline policies (embedded directly on a user, role, or group) and the permission content of customer-managed policies are not currently parsed, so privilege granted exclusively through those mechanisms will not be flagged.
Connection Requirements
AWS IAM User (Scanning Identity)
OrbisID authenticates using an IAM user with an access key. The IAM user should be a dedicated service account for OrbisID with read-only IAM permissions.
Recommended IAM policy:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "OrbisIDIAMReadOnly",
"Effect": "Allow",
"Action": [
"iam:ListUsers",
"iam:GetLoginProfile",
"iam:ListGroups",
"iam:ListRoles",
"iam:GetGroup",
"iam:ListAttachedUserPolicies",
"iam:ListAttachedRolePolicies",
"iam:ListAttachedGroupPolicies",
"iam:GetUser",
"iam:GenerateCredentialReport",
"iam:GetCredentialReport"
],
"Resource": "*"
}
]
}
Attach this policy to the dedicated IAM user and generate an Access Key ID and Secret Access Key.
If this system's credentials belong to the AWS Organizations management account (or an existing Firewall Manager admin), also add "fms:ListAdminAccountsForOrganization" to the statement above to additionally discover delegated FMS administrator accounts. This is optional — every other account will simply skip this step with a logged warning rather than fail the scan.
Credential Mapping
| OrbisID Field | AWS Value |
|---|---|
credential.username | IAM Access Key ID (e.g., AKIAIOSFODNN7EXAMPLE) |
credential.password | IAM Secret Access Key |
System Attributes
| Attribute | Required | Default | Description |
|---|---|---|---|
awsRegion | No | us-east-1 | AWS region for the IAM endpoint (IAM is global, but region is used for SigV4 signing) |
awsAccountId | No | — | AWS account ID (12-digit) — stored for reference in scan results |
Network Requirements
| Requirement | Detail |
|---|---|
| Outbound HTTPS | OrbisID server (or On-Premise Agent) must reach iam.amazonaws.com on port 443 |
Configuration Steps
- Create a dedicated IAM user (e.g.,
orbisid-scanner) in the AWS account - Attach the recommended IAM read-only policy
- Generate an Access Key for the IAM user — note the Access Key ID and Secret Access Key
- Create a Credential in OrbisID:
- Username: Access Key ID
- Password: Secret Access Key
- Navigate to Systems → Add System
- Fill in the fields:
| Field | Value |
|---|---|
| Name | Descriptive name (e.g., AWS – Production Account) |
| Hostname / IP Address | iam.amazonaws.com — pre-filled and locked; AWS IAM is a fixed global endpoint, not something you configure per system |
| OS Type | AWS |
| System Type | Infrastructure |
| Credential | The IAM user credential created above |
- Optionally, in the Connection Attributes section, set AWS Account ID (
awsAccountId) for reference - Click Test Connection — this calls
iam:GetUserwith the configured access key to confirm the credential actually authenticates, not just that the network path is reachable - Click Save
To scan multiple AWS accounts, add a separate OrbisID target system for each account with its own dedicated IAM user and access key.
Store the IAM Secret Access Key only in OrbisID's encrypted credential store. Do not share it across systems. Rotate access keys regularly and use a dedicated scanning-only IAM user with minimal permissions.
Real-Time Account & Entitlement Events
Beyond periodic full scans, OrbisID can drain an SQS queue (fed by CloudTrail via an EventBridge rule you configure) to detect IAM user create/delete and policy/group membership changes near-real-time. See Real-Time Events — Pro/Enterprise only. IAM has no clean "disable a user" concept, so account-enable/disable events aren't detected this way.
Troubleshooting
| Symptom | Likely Cause | Resolution |
|---|---|---|
InvalidClientTokenId | Access Key ID is invalid or deleted | Verify the access key exists and is active in the AWS console |
SignatureDoesNotMatch | Secret Access Key is incorrect | Regenerate or verify the secret access key |
AccessDenied | Missing IAM permissions | Attach the recommended policy; verify iam:ListUsers, iam:GetLoginProfile, iam:ListGroups, iam:ListRoles, iam:GetGroup, iam:ListAttachedGroupPolicies, iam:GetUser, iam:GenerateCredentialReport, iam:GetCredentialReport are allowed |
| No IAM users show console access, even ones you know have a password | Missing iam:GetLoginProfile permission | Console access is left undetermined (not assumed false) when this call is denied — check the scan's log viewer for a per-user warning, then attach iam:GetLoginProfile |
| Account root user missing from scan results | Credential report generation/retrieval failed or timed out | Check the scan's log viewer for the specific error (e.g. missing iam:GenerateCredentialReport/iam:GetCredentialReport permission); a very large account can occasionally take longer than OrbisID's 60-second poll window to generate a report for the first time — a subsequent scan will succeed once AWS has cached the report |
| No AWS Organizations FMS delegated administrator accounts discovered | Expected in almost all cases | This step only succeeds when scanning with credentials from the AWS Organizations management account (or an existing FMS admin) — an access-denied warning in the scan log for every other account is normal, not an error to fix |
| Connection refused / timeout | Network path to iam.amazonaws.com blocked | Check outbound firewall rules on port 443 from the OrbisID server or agent |
| No groups or users returned | Account has no IAM entities | Verify the correct AWS account is being scanned; check the access key belongs to the intended account |
certificate_unknown / "No subject alternative DNS name matching iam.amazonaws.com found" | A TLS-inspecting proxy, firewall, or VPN on the network path between the OrbisID server (or agent) and AWS is intercepting the connection and presenting its own certificate instead of Amazon's | Confirm what certificate is actually being served: openssl s_client -connect iam.amazonaws.com:443 -servername iam.amazonaws.com | openssl x509 -noout -subject -issuer -ext subjectAltName from the exact host/container running the scan. If the issuer isn't Amazon, work with network/security teams to exempt iam.amazonaws.com from TLS inspection, or route the scan through an On-Premise Agent on a network with a clean egress path |