standard
turbot/aws_compliance

Trigger: Detect & correct IAM users with inline policy

Detects IAM user with inline policy and deletes them.

Query

select
concat(i ->> 'PolicyName', ' [', account_id, ']') as title,
i ->> 'PolicyName' as inline_policy_name,
name as user_name,
account_id,
sp_connection_name as conn
from
aws_iam_user,
jsonb_array_elements(inline_policies) as i;

Schedule

15m

Tags

category = Compliance
mod = aws
service = AWS/IAM