SecurityAudit is enough
The AWS-managed read-only policy suffices. No custom permission set, no write access.
Check AWS accounts with read-only access
The connector reads an AWS account via the AWS SDK. You store an IAM user with the SecurityAudit managed policy, that is read-only access, plus the regions to be scanned. Findings are deduplicated per account, check and resource, and carry first and last seen timestamps.
Vendor: Amazon · docs.aws.amazon.com
The AWS-managed read-only policy suffices. No custom permission set, no write access.
If a complete run no longer finds a misconfiguration, the finding closes automatically. Manually decided ones stay closed.
We show you the connector live in your own environment – non-binding and free of charge.