Creating an External Access Analyzer
This section describes how to create an external access analyzer. After an external access analyzer is created, it automatically analyzes the policies attached to all principals within your zone of trust and generates findings for external access.
Constraints
Only the organization administrator and delegated administrator can create organization-level analyzers.
Creating an Access Analyzer with the Account as the Zone of Trust
- Log in to the new IAM console.
- In the navigation pane, choose Access Analyzer > Analyzers Settings, and click Create Analyzer.
Figure 1 Creating an access analyzer
- On the Create Analyzer page, select External access analysis for Analyzer Type in the Analysis area.
Figure 2 Selecting the external access analysis
- Enter an analyzer name.
Figure 3 Entering an analyzer name
- Select Current account for Zone of Trust. The access analyzer will analyze all supported resources in the zone of trust.
- (Optional) In the Tags area, click Add and enter a tag key and tag value.
- Click OK. The service-linked agency and access analyzer are created. The new access analyzer will be displayed in the analyzer list.
Creating an Access Analyzer with the Organization as the Zone of Trust
- Log in to the new IAM console.
- In the navigation pane, choose Access Analyzer > Analyzers Settings, and click Create Analyzer.
Figure 4 Creating an access analyzer
- On the Create Analyzer page, select External access analysis for Analyzer Type in the Analysis area.
Figure 5 Selecting the external access analysis
- Enter an analyzer name.
Figure 6 Entering an analyzer name
- Select Current organization for Zone of Trust. The access analyzer will analyze all supported resources in the zone of trust.
- (Optional) Click View Permission Details to view the service-linked agency that is created along with an organization-level analyzer.
When an organization-level analyzer is created, trusted services are enabled on the Organizations console, and a service-linked agency is created for all accounts in the organization. The service-linked agency then grants the analyzer permissions for interacting with resources on your behalf.
Figure 7 Service-linked agency details
- (Optional) In the Tags area, click Add and enter a tag key and tag value.
- Click OK. The new access analyzer will be displayed in the analyzer list.
Follow-Up Operations
After an access analyzer is created, you can go to the External Access page to view the findings and perform other operations as needed.

Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot