Low IAM Regional

IAM Access Analyzer analyzers should be tagged

Description

Flags IAM Access Analyzer analyzers that have no user-defined tags. Tags help associate analyzers with their owning team and scope; untagged analyzers are operationally opaque.


Remediation

Apply at least one user-defined tag to every IAM Access Analyzer analyzer.

Steps

  1. Open the IAM Access Analyzer console.
  2. Choose Analyzers, then select the affected analyzer.
  3. Open the Tags section and choose Manage tags.
  4. Add at least one tag with a non-aws: prefixed key.
  5. Save the changes.