Updated on 2024-05-16 GMT+08:00

Unintended Policy Check

Rule Details

Table 1 Rule details

Parameter

Description

Rule Name

iam-policy-blacklisted-check

Identifier

iam-policy-blacklisted-check

Description

If any specified policies are attached to an IAM user or user group or are included in an IAM agency, the result is noncompliant.

Tag

iam

Trigger Type

Configuration change

Filter Type

iam.users, iam.groups, iam.agencies

Configure Rule Parameters

blackListPolicyUrns: indicates a policy list. The value must be an array.