Skip to main content

📗 AWS IAM User

  • Contextual name: 📗 AWS IAM User
  • ID: /types/CA10__CaAwsUser__c

Fields

LabelAPI NameTypeHelp
🔒ARNCA10__arn__cLongTextArea(32768)API Call: iam:ListUsers
🔒ARNCA10__arn2__cText(255)API Call: iam:ListUsers
🔒Access Keys CountCA10__accessKeysCount__cNumber(18, 0)API Call: iam:ListAccessKeys
🔒🧮ApplicationCA10__application__cText(1300)
🔒Application Tier Api NameCA10__applicationTierApiName__cText(255)
🔒Application Tier Cascade AttachCA10__applicationTierCascadeAttach__cCheckbox
🔒Application Tier Parent TypeCA10__applicationTierParentType__cText(255)
🔒Application Tier Parent UUIDCA10__applicationTierParentUuid__cText(255)
🔒Application Tier Unique NameCA10__applicationTierUniqueName__cText(255)
🔒Approval StatusCA10__approveStatus__cText(255)
🔒Approve DateCA10__approveDate__cDateTime
🔒CloudAware UUIDCA10__caUuid__cText(36)
🔒CloudAware UsagesCA10__caUsages__cText(255)
🔒Create DateCA10__createDate__cDateTimeAPI Call: iam:ListUsers
🔒Created DateCreatedDateDateTime
🔒🔌Cred Report: Access Key #1 ActiveCA10__credReportAccessKey1Active__cCheckboxAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒Cred Report: Access Key #1 Last RegionCA10__credReportAccessKey1LastRegion__cText(255)API Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒🔌Cred Report: Access Key #1 Last RotatedCA10__credReportAccessKey1LastRotated__cDateTimeAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒Cred Report: Access Key #1 Last ServiceCA10__credReportAccessKey1LastService__cText(255)API Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒🔌Cred Report: Access Key #1 Last UsedCA10__credReportAccessKey1LastUsed__cDateTimeAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒🔌Cred Report: Access Key #2 ActiveCA10__credReportAccessKey2Active__cCheckboxAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒Cred Report: Access Key #2 Last RegionCA10__credReportAccessKey2LastRegion__cText(255)API Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒🔌Cred Report: Access Key #2 Last RotatedCA10__credReportAccessKey2LastRotated__cDateTimeAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒Cred Report: Access Key #2 Last ServiceCA10__credReportAccessKey2LastService__cText(255)API Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒🔌Cred Report: Access Key #2 Last UsedCA10__credReportAccessKey2LastUsed__cDateTimeAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒Cred Report: AttributesCA10__credReportAttributes__cLongTextArea(32768)API Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒🔌Cred Report: Attributes JSONCA10__credReportAttributesJson__cLongTextArea(32768)
JSON
API Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒Cred Report: Cert #1 ActiveCA10__credReportCert1Active__cCheckboxAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒Cred Report: Cert #1 Last RotatedCA10__credReportCert1LastRotated__cDateTimeAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒Cred Report: Cert #2 ActiveCA10__credReportCert2Active__cCheckboxAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒Cred Report: Cert #2 Last RotatedCA10__credReportCert2LastRotated__cDateTimeAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒Cred Report: Generated TimeCA10__credReportGeneratedTime__cDateTimeAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒🔌Cred Report: MFA ActiveCA10__credReportMfaActive__cCheckboxAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒🔌Cred Report: Password EnabledCA10__credReportPasswordEnabled__cCheckboxAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒🔌Cred Report: Password Last ChangedCA10__credReportPasswordLastChanged__cDateTimeAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒🔌Cred Report: Password Last UsedCA10__credReportPasswordLastUsed__cDateTimeAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒Cred Report: Password Next RotationCA10__credReportPasswordNextRotation__cDateTimeAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒Cred Report: User Creation TimeCA10__credReportUserCreationTime__cDateTimeAPI Call: iam:GenerateCredentialReport, iam:GetCredentialReport
🔒🧮Days Since Last AWS AccessCA10__daysSinceLastAwsAccess__cNumber(18, 0)
🔒DeletedIsDeletedCheckbox
🔒Deleted From AWSCA10__disappearanceTime__cDateTime
🔒Deprecated: Chatter IgnoreCA10__chatterIgnore__cCheckbox
🔒Deprecated: Created By ARNCA10__createdByArn__cText(255)
🔒Deprecated: Created By User ARNCA10__createdByUserArn__cText(255)
🔒Deprecated: Created DateCA10__createdDate__cDateTime
🔒🧮Deprecated: IAM-OPT-083 CompliantCA10__policy083Compliant__cText(1300)
🔒🧮Deprecated: IAM-ST-026 CompliantCA10__policy024Compliant__cText(1300)
🔒🧮Deprecated: IAM-ST-080 CompliantCA10__policy080Compliant__cText(1300)
🔒Deprecated: Individual Policies CountCA10__individualPoliciesCount__cNumber(18, 0)
🔒Deprecated: Last AWS AccessCA10__lastAwsAccess__cDateTime
🔒Deprecated: Last Login Date TimeCA10__lastLoginDateTime__cDateTime
🔒Deprecated: Name In Email FormatCA10__nameInEmailFormat__cCheckbox
🔒Fire Change TriggerCA10__fireChangeTrigger__cDateTime
🔒Hardware MFA Enable DateCA10__hardwareMfaEnableDate__cDateTimeAPI Call: iam:ListMFADevices
🔒Hardware MFA Serial NumberCA10__hardwareMfaSerialNumber__cText(255)API Call: iam:ListMFADevices
🔒Hardware MFA StateCA10__hardwareMfaState__cText(255)
🔒Has API AccessCA10__hasKeys__cCheckboxAPI Call: iam:ListAccessKeys
🔒Last Activity DateLastActivityDateDate
🔒Last Modified DateLastModifiedDateDateTime
🔒Login Profile Create DateCA10__loginProfileCreateDate__cDateTimeAPI Call: iam:GetLoginProfile
🔒🔌MFA Device TypeCA10__mfaDeviceType__cText(255)
🔒MFA Enable DateCA10__mfaEnableDate__cDateTimeAPI Call: iam:ListMFADevices
🔒MFA Serial NumberCA10__mfaSerialNumber__cText(255)API Call: iam:ListMFADevices
🔒Password Last UsedCA10__passwordLastUsed__cDateTimeAPI Call: iam:ListUsers
🔒Password Reset RequiredCA10__passwordResetRequired__cText(255)API Call: iam:GetLoginProfile
🔒PathCA10__path__cLongTextArea(32768)API Call: iam:ListUsers
🔒Permissions Boundary: ARNCA10A1__permissionsBoundaryArn__cLongTextArea(32768)API Call: iam:ListUsers
🔒Permissions Boundary: TypeCA10A1__permissionsBoundaryType__cText(255)API Call: iam:ListUsers
🔒Record IDIdText
🔒System ModstampSystemModstampDateTime
🔒Tag CountCA10__tagCount__cNumber(18, 0)API Call: iam:ListUserTags
🔒TagsCA10__tags__cLongTextArea(131072)API Call: iam:ListUserTags
🔒Tags JSONCA10__tagsJson__cLongTextArea(131072)API Call: iam:ListUserTags
🔒User IDCA10__userId__cText(255)API Call: iam:ListUsers
🔒User NameNameText(80)API Call: iam:ListUsers
🔒🔌User NameCA10__userName__cText(255)API Call: iam:ListUsers
🔒Virtual MFA Enable DateCA10__virtualMfaEnableDate__cDateTimeAPI Call: iam:ListVirtualMFADevices
🔒Virtual MFA Serial NumberCA10__virtualMfaSerialNumber__cText(255)API Call: iam:ListVirtualMFADevices
🔒Virtual MFA StateCA10__virtualMfaState__cText(255)

Extracts

NameExtracts File
🔒CA10__credReportAccessKey1Active__c🔌 credReport.extracts.yaml
🔒CA10__credReportAccessKey1LastRotated__c🔌 credReport.extracts.yaml
🔒CA10__credReportAccessKey1LastUsed__c🔌 credReport.extracts.yaml
🔒CA10__credReportAccessKey2Active__c🔌 credReport.extracts.yaml
🔒CA10__credReportAccessKey2LastRotated__c🔌 credReport.extracts.yaml
🔒CA10__credReportAccessKey2LastUsed__c🔌 credReport.extracts.yaml
🔒CA10__credReportAttributesJson__c🔌 credReport.extracts.yaml
🔒CA10__credReportMfaActive__c🔌 credReport.extracts.yaml
🔒CA10__credReportPasswordEnabled__c🔌 credReport.extracts.yaml
🔒CA10__credReportPasswordLastChanged__c🔌 credReport.extracts.yaml
🔒CA10__credReportPasswordLastUsed__c🔌 credReport.extracts.yaml
🔒CA10__mfaDeviceType__c🔌 object.extracts.yaml
🔒CA10__userName__c🔌 object.extracts.yaml

Lookups

LabelAPI NameType
🔒AccountCA10__account__c / CA10__account__r📗 AWS Account
🔒Application TierCA10__applicationTier__c / CA10__applicationTier__rCA10__CaApplicationTier__c
🔒Created By IDCreatedById / CreatedByUser
🔒Deprecated: Created By UserCA10__createdByUser__c / CA10__createdByUser__r📗 AWS IAM User
🔒Last Modified By IDLastModifiedById / LastModifiedByUser
🔒Permissions BoundaryCA10A1__permissionsBoundary__c / CA10A1__permissionsBoundary__r📗 AWS IAM Policy
🔒Received Connection IDConnectionReceivedId / ConnectionReceivedPartnerNetworkConnection
🔒Record Type IDRecordTypeId / RecordTypeRecordType
🔒Sent Connection IDConnectionSentId / ConnectionSentPartnerNetworkConnection
Related TypeRelated List API NameForeign Key Field
🔒📗 AWS AccountCA10__AWS_Accounts__rCA10__user__c
🔒📗 AWS RDS InstanceCA10__AWS_RDS_Instances__rCA10__createdByUser__c
🔒📗 AWS EC2 ImageCA10__AWS_EC2_Images__rCA10__createdByUser__c
🔒📗 AWS EC2 InstanceCA10__AWS_EC2_Instances__rCA10__createdByUser__c
🔒📗 AWS ELB Load BalancerCA10__AWS_EC2_Load_Balancers__rCA10__createdByUser__c
🔒📗 AWS VPC Network ACLCA10__AWS_VPC_Network_ACLs__rCA10__createdByUser__c
🔒📗 AWS IAM RoleCA10__AWS_IAM_Roles__rCA10__createdByUser__c
🔒📗 AWS EC2 Security Group RuleCA10__AWS_EC2_Security_Group_Rules1__rCA10__createdByUser__c
🔒📗 AWS EC2 Security GroupCA10__AWS_EC2_Security_Groups__rCA10__createdByUser__c
🔒📗 AWS EBS SnapshotCA10__AWS_EBS_Snapshots__rCA10__createdByUser__c
🔒📗 AWS VPC SubnetCA10__AWS_EC2_Subnets__rCA10__createdByUser__c
🔒📗 AWS IAM UserCA10__AWS_IAM_Users__rCA10__createdByUser__c
🔒📗 AWS EBS VolumeCA10__AWS_EBS_Volumes__rCA10__createdByUser__c
🔒📗 AWS VPCCA10__AWS_VPCs__rCA10__createdByUser__c

Extract Files

ExtractParentyFlags
🔌 credReport.extracts.yaml📗 AWS IAM User
🔌 object.extracts.yaml📗 AWS IAM User

Logic Files

LogicPolicyFlags
🧠 prod.logic.yaml 🟢📝 AWS Account Root User credentials were used is the last 30 days 🟢🟢 x3
🧠 prod.logic.yaml 🟢📝 AWS Account Root User has active access keys 🟢🟢 x3
🧠 prod.logic.yaml 🟢📝 AWS Account Root User MFA is not enabled. 🟢🟢 x3
🧠 prod.logic.yaml 🟢📝 AWS IAM User Access Keys are not rotated every 90 days or less 🟢🟢 x3
🧠 prod.logic.yaml 🟠🟢📝 AWS IAM User has inline or directly attached policies 🟢🟠 x1, 🟢 x2
🧠 prod.logic.yaml 🟢📝 AWS IAM User has more than one active access key 🟢🟢 x3
🧠 prod.logic.yaml 🟢📝 AWS IAM User MFA is not enabled for all users with console password 🟢🟢 x3
🧠 prod.logic.yaml 🟢📝 AWS IAM User with credentials unused for 45 days or more is not disabled 🟢🟢 x3