Right-size a role from its own activity
ReportsExportRole is allowed forty-two actions. In Policy from activity, the ninety-day trail shows the calls it actually made.
Toggle the highlight to see which of the granted actions the trail used, then generate the least-privilege policy and watch the reach fall from forty-two down to three.
IAM Access Analyzer runs this same comparison for you, though it emits resource placeholders you fill in and cannot see S3 object reads at all.
What is the one thing that trail cannot tell you?
Bài tập này là một phần của khóa học
Using AWS Security for Developers
Bài tập tương tác thực hành
Biến lý thuyết thành hành động với một trong các bài tập tương tác của chúng tôi
Bắt đầu bài tập