Unused cloud permissions are latent attack paths
Permissions that have never been used are still permissions.
Cloud providers record what each account actually does, which means you can compare granted against used, and the gap is usually enormous. Every unused permission does nothing for the business and everything for whoever takes the account. It is one of the few security clean-ups with a genuinely low risk of breaking anything, because by definition nobody has been using it.
More on Cloud IAM
- Cloud roles can replace copied long-lived keysStop posting copies. Hand out passes
- Resource policies create a second authorisation surfaceThe thing has a policy too
- Permission boundaries cap delegated powerGrant what you like. It stops at the rail
- Organisation guardrails prevent dangerous local choicesThe wrong setting is not on the dial
- Cross-account trust expands the identity perimeterYour perimeter now runs round their office
- Console access and workload access are different pathsTwo doors, one room
