Skip to main content

๐Ÿ“• AWS IAM User

  • Contextual name: ๐Ÿ“• AWS IAM User
  • ID: /types/CA10__CaAwsUser__c

Fieldsโ€‹

LabelAPI NameTypeHelp
๐Ÿ”’ARNCA10__arn__cLongTextArea(32768)API Call: iam:ListUsers
๐Ÿ”’ARNCA10__arn2__cText(255)API Call: iam:ListUsers
๐Ÿ”’Access Keys CountCA10__accessKeysCount__cNumber(18, 0)API Call: iam:ListAccessKeys
๐Ÿ”’๐ŸงฎApplicationCA10__application__cText(1300)
๐Ÿ”’Application Tier Api NameCA10__applicationTierApiName__cText(255)
๐Ÿ”’Application Tier Cascade AttachCA10__applicationTierCascadeAttach__cCheckbox
๐Ÿ”’Application Tier Parent TypeCA10__applicationTierParentType__cText(255)
๐Ÿ”’Application Tier Parent UUIDCA10__applicationTierParentUuid__cText(255)
๐Ÿ”’Application Tier Unique NameCA10__applicationTierUniqueName__cText(255)
๐Ÿ”’Approval StatusCA10__approveStatus__cText(255)
๐Ÿ”’Approve DateCA10__approveDate__cDateTime
๐Ÿ”’CloudAware UUIDCA10__caUuid__cText(36)
๐Ÿ”’CloudAware UsagesCA10__caUsages__cText(255)
๐Ÿ”’Create DateCA10__createDate__cDateTimeAPI Call: iam:ListUsers
๐Ÿ”’Created DateCreatedDateDateTime
๐Ÿ”’๐Ÿ”ŒCred Report: Access Key #1 ActiveCA10__credReportAccessKey1Active__cCheckboxAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’Cred Report: Access Key #1 Last RegionCA10__credReportAccessKey1LastRegion__cText(255)API Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’๐Ÿ”ŒCred Report: Access Key #1 Last RotatedCA10__credReportAccessKey1LastRotated__cDateTimeAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’Cred Report: Access Key #1 Last ServiceCA10__credReportAccessKey1LastService__cText(255)API Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’๐Ÿ”ŒCred Report: Access Key #1 Last UsedCA10__credReportAccessKey1LastUsed__cDateTimeAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’๐Ÿ”ŒCred Report: Access Key #2 ActiveCA10__credReportAccessKey2Active__cCheckboxAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’Cred Report: Access Key #2 Last RegionCA10__credReportAccessKey2LastRegion__cText(255)API Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’๐Ÿ”ŒCred Report: Access Key #2 Last RotatedCA10__credReportAccessKey2LastRotated__cDateTimeAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’Cred Report: Access Key #2 Last ServiceCA10__credReportAccessKey2LastService__cText(255)API Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’๐Ÿ”ŒCred Report: Access Key #2 Last UsedCA10__credReportAccessKey2LastUsed__cDateTimeAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’Cred Report: AttributesCA10__credReportAttributes__cLongTextArea(32768)API Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’๐Ÿ”ŒCred Report: Attributes JSONCA10__credReportAttributesJson__cLongTextArea(32768)
JSON
API Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’Cred Report: Cert #1 ActiveCA10__credReportCert1Active__cCheckboxAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’Cred Report: Cert #1 Last RotatedCA10__credReportCert1LastRotated__cDateTimeAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’Cred Report: Cert #2 ActiveCA10__credReportCert2Active__cCheckboxAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’Cred Report: Cert #2 Last RotatedCA10__credReportCert2LastRotated__cDateTimeAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’Cred Report: Generated TimeCA10__credReportGeneratedTime__cDateTimeAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’๐Ÿ”ŒCred Report: MFA ActiveCA10__credReportMfaActive__cCheckboxAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’๐Ÿ”ŒCred Report: Password EnabledCA10__credReportPasswordEnabled__cCheckboxAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’๐Ÿ”ŒCred Report: Password Last ChangedCA10__credReportPasswordLastChanged__cDateTimeAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’๐Ÿ”ŒCred Report: Password Last UsedCA10__credReportPasswordLastUsed__cDateTimeAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’Cred Report: Password Next RotationCA10__credReportPasswordNextRotation__cDateTimeAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’Cred Report: User Creation TimeCA10__credReportUserCreationTime__cDateTimeAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
๐Ÿ”’๐ŸงฎDays Since Last AWS AccessCA10__daysSinceLastAwsAccess__cNumber(18, 0)
๐Ÿ”’DeletedIsDeletedCheckbox
๐Ÿ”’Deleted From AWSCA10__disappearanceTime__cDateTime
๐Ÿ”’Deprecated: Chatter IgnoreCA10__chatterIgnore__cCheckbox
๐Ÿ”’Deprecated: Created By ARNCA10__createdByArn__cText(255)
๐Ÿ”’Deprecated: Created By User ARNCA10__createdByUserArn__cText(255)
๐Ÿ”’Deprecated: Created DateCA10__createdDate__cDateTime
๐Ÿ”’๐ŸงฎDeprecated: IAM-OPT-083 CompliantCA10__policy083Compliant__cText(1300)
๐Ÿ”’๐ŸงฎDeprecated: IAM-ST-026 CompliantCA10__policy024Compliant__cText(1300)
๐Ÿ”’๐ŸงฎDeprecated: IAM-ST-080 CompliantCA10__policy080Compliant__cText(1300)
๐Ÿ”’Deprecated: Individual Policies CountCA10__individualPoliciesCount__cNumber(18, 0)
๐Ÿ”’Deprecated: Last AWS AccessCA10__lastAwsAccess__cDateTime
๐Ÿ”’Deprecated: Last Login Date TimeCA10__lastLoginDateTime__cDateTime
๐Ÿ”’Deprecated: Name In Email FormatCA10__nameInEmailFormat__cCheckbox
๐Ÿ”’Fire Change TriggerCA10__fireChangeTrigger__cDateTime
๐Ÿ”’Hardware MFA Enable DateCA10__hardwareMfaEnableDate__cDateTimeAPI Call: iam:ListMFADevices
๐Ÿ”’Hardware MFA Serial NumberCA10__hardwareMfaSerialNumber__cText(255)API Call: iam:ListMFADevices
๐Ÿ”’Hardware MFA StateCA10__hardwareMfaState__cText(255)
๐Ÿ”’Has API AccessCA10__hasKeys__cCheckboxAPI Call: iam:ListAccessKeys
๐Ÿ”’Last Activity DateLastActivityDateDate
๐Ÿ”’Last Modified DateLastModifiedDateDateTime
๐Ÿ”’Login Profile Create DateCA10__loginProfileCreateDate__cDateTimeAPI Call: iam:GetLoginProfile
๐Ÿ”’๐Ÿ”ŒMFA Device TypeCA10__mfaDeviceType__cText(255)
๐Ÿ”’MFA Enable DateCA10__mfaEnableDate__cDateTimeAPI Call: iam:ListMFADevices
๐Ÿ”’MFA Serial NumberCA10__mfaSerialNumber__cText(255)API Call: iam:ListMFADevices
๐Ÿ”’Password Last UsedCA10__passwordLastUsed__cDateTimeAPI Call: iam:ListUsers
๐Ÿ”’Password Reset RequiredCA10__passwordResetRequired__cText(255)API Call: iam:GetLoginProfile
๐Ÿ”’PathCA10__path__cLongTextArea(32768)API Call: iam:ListUsers
๐Ÿ”’Permissions Boundary: ARNCA10A1__permissionsBoundaryArn__cLongTextArea(32768)API Call: iam:ListUsers
๐Ÿ”’Permissions Boundary: TypeCA10A1__permissionsBoundaryType__cText(255)API Call: iam:ListUsers
๐Ÿ”’Record IDIdText
๐Ÿ”’System ModstampSystemModstampDateTime
๐Ÿ”’Tag CountCA10__tagCount__cNumber(18, 0)API Call: iam:ListUserTags
๐Ÿ”’TagsCA10__tags__cLongTextArea(131072)API Call: iam:ListUserTags
๐Ÿ”’Tags JSONCA10__tagsJson__cLongTextArea(131072)API Call: iam:ListUserTags
๐Ÿ”’User IDCA10__userId__cText(255)API Call: iam:ListUsers
๐Ÿ”’User NameNameText(80)API Call: iam:ListUsers
๐Ÿ”’๐Ÿ”ŒUser NameCA10__userName__cText(255)API Call: iam:ListUsers
๐Ÿ”’Virtual MFA Enable DateCA10__virtualMfaEnableDate__cDateTimeAPI Call: iam:ListVirtualMFADevices
๐Ÿ”’Virtual MFA Serial NumberCA10__virtualMfaSerialNumber__cText(255)API Call: iam:ListVirtualMFADevices
๐Ÿ”’Virtual MFA StateCA10__virtualMfaState__cText(255)

Extractsโ€‹

NameExtracts File
๐Ÿ”’CA10__credReportAccessKey1Active__c๐Ÿ”Œ credReport.extracts.yaml
๐Ÿ”’CA10__credReportAccessKey1LastRotated__c๐Ÿ”Œ credReport.extracts.yaml
๐Ÿ”’CA10__credReportAccessKey1LastUsed__c๐Ÿ”Œ credReport.extracts.yaml
๐Ÿ”’CA10__credReportAccessKey2Active__c๐Ÿ”Œ credReport.extracts.yaml
๐Ÿ”’CA10__credReportAccessKey2LastRotated__c๐Ÿ”Œ credReport.extracts.yaml
๐Ÿ”’CA10__credReportAccessKey2LastUsed__c๐Ÿ”Œ credReport.extracts.yaml
๐Ÿ”’CA10__credReportAttributesJson__c๐Ÿ”Œ credReport.extracts.yaml
๐Ÿ”’CA10__credReportMfaActive__c๐Ÿ”Œ credReport.extracts.yaml
๐Ÿ”’CA10__credReportPasswordEnabled__c๐Ÿ”Œ credReport.extracts.yaml
๐Ÿ”’CA10__credReportPasswordLastChanged__c๐Ÿ”Œ credReport.extracts.yaml
๐Ÿ”’CA10__credReportPasswordLastUsed__c๐Ÿ”Œ credReport.extracts.yaml
๐Ÿ”’CA10__mfaDeviceType__c๐Ÿ”Œ object.extracts.yaml
๐Ÿ”’CA10__userName__c๐Ÿ”Œ object.extracts.yaml

Lookupsโ€‹

LabelAPI NameType
๐Ÿ”’AccountCA10__account__c / CA10__account__r๐Ÿ“• AWS Account
๐Ÿ”’Application TierCA10__applicationTier__c / CA10__applicationTier__rCA10__CaApplicationTier__c
๐Ÿ”’Created By IDCreatedById / CreatedByUser
๐Ÿ”’Deprecated: Created By UserCA10__createdByUser__c / CA10__createdByUser__r๐Ÿ“• AWS IAM User
๐Ÿ”’Last Modified By IDLastModifiedById / LastModifiedByUser
๐Ÿ”’Permissions BoundaryCA10A1__permissionsBoundary__c / CA10A1__permissionsBoundary__r๐Ÿ“• AWS IAM Policy
๐Ÿ”’Received Connection IDConnectionReceivedId / ConnectionReceivedPartnerNetworkConnection
๐Ÿ”’Record Type IDRecordTypeId / RecordTypeRecordType
๐Ÿ”’Sent Connection IDConnectionSentId / ConnectionSentPartnerNetworkConnection
Related TypeRelated List API NameForeign Key Field
๐Ÿ”’๐Ÿ“• AWS AccountCA10__AWS_Accounts__rCA10__user__c
๐Ÿ”’๐Ÿ“• AWS RDS InstanceCA10__AWS_RDS_Instances__rCA10__createdByUser__c
๐Ÿ”’๐Ÿ“• AWS EC2 ImageCA10__AWS_EC2_Images__rCA10__createdByUser__c
๐Ÿ”’๐Ÿ“• AWS EC2 InstanceCA10__AWS_EC2_Instances__rCA10__createdByUser__c
๐Ÿ”’๐Ÿ“• AWS ELB Load BalancerCA10__AWS_EC2_Load_Balancers__rCA10__createdByUser__c
๐Ÿ”’๐Ÿ“• AWS VPC Network ACLCA10__AWS_VPC_Network_ACLs__rCA10__createdByUser__c
๐Ÿ”’๐Ÿ“• AWS IAM RoleCA10__AWS_IAM_Roles__rCA10__createdByUser__c
๐Ÿ”’๐Ÿ“• AWS EC2 Security Group RuleCA10__AWS_EC2_Security_Group_Rules1__rCA10__createdByUser__c
๐Ÿ”’๐Ÿ“• AWS EC2 Security GroupCA10__AWS_EC2_Security_Groups__rCA10__createdByUser__c
๐Ÿ”’๐Ÿ“• AWS EBS SnapshotCA10__AWS_EBS_Snapshots__rCA10__createdByUser__c
๐Ÿ”’๐Ÿ“• AWS IAM UserCA10__AWS_IAM_Users__rCA10__createdByUser__c
๐Ÿ”’๐Ÿ“• AWS EBS VolumeCA10__AWS_EBS_Volumes__rCA10__createdByUser__c
๐Ÿ”’๐Ÿ“• AWS VPCCA10__AWS_VPCs__rCA10__createdByUser__c

Extract Filesโ€‹

ExtractTypeFlags
๐Ÿ”Œ credReport.extracts.yaml๐Ÿ“• AWS IAM User
๐Ÿ”Œ object.extracts.yaml๐Ÿ“• AWS IAM User

Logic Filesโ€‹

LogicPolicyFlags
๐Ÿง  prod.logic.yaml ๐ŸŸข๐Ÿ“ AWS Account Root User credentials were used is the last 30 days ๐Ÿ”ด๐ŸŸข๐ŸŸข x3
๐Ÿง  prod.logic.yaml ๐ŸŸข๐Ÿ“ AWS Account Root User has active access keys ๐ŸŸข๐ŸŸข x3
๐Ÿง  prod.logic.yaml ๐ŸŸข๐Ÿ“ AWS Account Root User MFA is not enabled. ๐ŸŸข๐ŸŸข x3
๐Ÿง  prod.logic.yaml ๐ŸŸข๐Ÿ“ AWS IAM User Access Keys are not rotated every 90 days or less ๐ŸŸข๐ŸŸข x3
๐Ÿง  prod.logic.yaml ๐ŸŸ ๐ŸŸข๐Ÿ“ AWS IAM User has inline or directly attached policies ๐ŸŸข๐ŸŸ  x1, ๐ŸŸข x2
๐Ÿง  prod.logic.yaml ๐ŸŸข๐Ÿ“ AWS IAM User has more than one active access key ๐ŸŸข๐ŸŸข x3
๐Ÿง  prod.logic.yaml ๐ŸŸข๐Ÿ“ AWS IAM User MFA is not enabled for all users with console password ๐ŸŸข๐ŸŸข x3
๐Ÿง  prod.logic.yaml ๐ŸŸข๐Ÿ“ AWS IAM User with credentials unused for 45 days or more is not disabled ๐ŸŸข๐ŸŸข x3