Low
IAM
Regional
IAM Access Analyzer analyzers should be tagged
Description
Flags IAM Access Analyzer analyzers that have no user-defined tags. Tags help associate analyzers with their owning team and scope; untagged analyzers are operationally opaque.
Remediation
Apply at least one user-defined tag to every IAM Access Analyzer analyzer.
Steps
- Open the IAM Access Analyzer console.
- Choose Analyzers, then select the affected analyzer.
- Open the Tags section and choose Manage tags.
- Add at least one tag with a non-aws: prefixed key.
- Save the changes.