aws-iam-best-practices - AWS IAM Policy Review, Hardening & Least Privilege
Review and harden IAM policies following AWS security best practices and least privilege principles.
Tags
Updated: 2026-06-30Capabilities
Typical Inputs
Typical Outputs
What this skill does
- review IAM policies
- find overly permissive policies
- list users without MFA
- create virtual MFA devices
- find old access keys
- rotate access keys
- list unused IAM roles
- find roles with external trust
- simulate principal policy permissions
- generate IAM hardening reports
- create least privilege policy templates
- enforce MFA requirements
Inputs
- AWS account credentials
- IAM policies
- IAM user list
- IAM role list
- Access key metadata
- CloudTrail logs
Outputs
- IAM hardening report
- security findings on permissive policies
- list of users without MFA
- list of expired access keys
- IAM policy templates in JSON
- MFA QR code image
Requirements
- AWS CLI installed and configured
- AWS IAM read permissions
- Python with boto3 for automated hardening
- kiro-cli for CLI integration (optional)
