AWS Security Hub detects unused IAM permissions
AWS Security Hub now identifies unused IAM permissions, roles, and credentials across your organization, centralizing identity risk management within the existing console. This feature helps security teams reduce identity risk at scale by correlating unused permissions with actual resource exposure. It is automatically enabled via a service-linked IAM Access Analyzer in each member account and included with Security Hub Essentials at no additional cost.
- →Unified identity risk detection in Security Hub
- →Automated unused access analysis
- →Least-privilege policy generation
- →Foundational step for Cloud Infrastructure Entitlement Management
- →Included with Security Hub Essentials
Features (3) ›
- Unified identity risk detection in Security Hub
AWS Security Hub now integrates identity risk detection by identifying unused IAM permissions, roles, and credentials directly within its unified console. This allows central security teams to manage identity risks alongside existing threat, exposure, and posture findings.
- Automated unused access analysis
A service-linked IAM Access Analyzer is automatically created in each member account when Security Hub is enabled for an organization. It evaluates IAM principals against 90 days of access activity to detect unused access and correlate it with exposure context.
- Least-privilege policy generation
Security Hub provides on-demand generation of recommended least-privilege policies based on actual IAM usage patterns. This assists teams in refining permissions and reducing their attack surface.
Notes (2) ›
- Foundational step for Cloud Infrastructure Entitlement Management
These new capabilities are presented as a foundational step toward broader Cloud Infrastructure Entitlement Management (CIEM) within Security Hub. They are delivered with consistent workflows, automation rules, and downstream integrations.
- Included with Security Hub Essentials
The new identity risk detection features are included with Security Hub Essentials at no additional cost. Further details can be found in the AWS Security Hub User Guide and product page.
https://aws.amazon.com/about-aws/whats-new/2026/05/aws-security-hub-unused-access/
Related releases
- SageMaker Unified Studio Enhances Git Version Control Across Project Tools AWS What's New ·
- IAM Policy Simulator integrated into IAM console with new features AWS What's New ·
- AWS IAM Identity Center adds multi-Region replication for its own directory AWS What's New ·
- Amazon EKS supports AWS PrivateLink for OIDC endpoint AWS What's New ·
- Amazon Neptune adds IAM tag-based access control for data plane operations AWS What's New ·
- Amazon Bedrock AgentCore enables unified observability for AI agents AWS What's New ·