Skip to content

aws.accessanalyzer.list_access_preview_findings

Example SQL Queries

SELECT * FROM
aws.accessanalyzer.list_access_preview_findings
WHERE
"access_preview_id" = 'VALUE'
AND "analyzer_arn" = 'VALUE';

Description

Retrieves a list of access preview findings generated by the specified access preview.

Table Definition

Column NameColumn Data Type
access_preview_id Required Input Column

The unique ID for the access preview.

VARCHAR
analyzer_arn Required Input Column

The ARN of the analyzer used to generate the access.

VARCHAR
filter Input Column

Criteria to filter the returned findings.

MAP(VARCHAR, STRUCT(
"eq" VARCHAR[],
"neq" VARCHAR[],
"contains" VARCHAR[],
"exists" BOOLEAN
))
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

action

The action in the analyzed policy statement that an external principal has permission to perform.

VARCHAR[]
Show child fields
action[]
change_type

Provides context on how the access preview finding compares to existing access identified in IAM Access Analyzer.

  • New - The finding is for newly-introduced access.

  • Unchanged - The preview finding is an existing finding that would remain unchanged.

  • Changed - The preview finding is an existing finding with a change in status.

For example, a Changed finding with preview status Resolved and existing status Active indicates the existing Active finding would become Resolved as a result of the proposed permissions change.

VARCHAR
condition

The condition in the analyzed policy statement that resulted in a finding.

MAP(VARCHAR, VARCHAR)
created_at

The time at which the access preview finding was created.

TIMESTAMP_S
error

An error.

VARCHAR
existing_finding_id

The existing ID of the finding in IAM Access Analyzer, provided only for existing findings.

VARCHAR
existing_finding_status

The existing status of the finding, provided only for existing findings.

VARCHAR
id

The ID of the access preview finding. This ID uniquely identifies the element in the list of access preview findings and is not related to the finding ID in Access Analyzer.

VARCHAR
is_public

Indicates whether the policy that generated the finding allows public access to the resource.

BOOLEAN
principal

The external principal that has access to a resource within the zone of trust.

MAP(VARCHAR, VARCHAR)
resource

The resource that an external principal has access to. This is the resource associated with the access preview.

VARCHAR
resource_owner_account

The Amazon Web Services account ID that owns the resource. For most Amazon Web Services resources, the owning account is the account in which the resource was created.

VARCHAR
resource_type

The type of the resource that can be accessed in the finding.

VARCHAR
sources

The sources of the finding. This indicates how the access that generated the finding is granted. It is populated for Amazon S3 bucket findings.

STRUCT(
"type" VARCHAR,
"detail" STRUCT(
"access_point_arn" VARCHAR,
"access_point_account" VARCHAR
)
)[]
Show child fields
sources[]
Show child fields
sources[].detail

Includes details about how the access that generated the finding is granted. This is populated for Amazon S3 bucket findings.

Show child fields
sources[].detail.access_point_account

The account of the cross-account access point that generated the finding.

sources[].detail.access_point_arn

The ARN of the access point that generated the finding. The ARN format depends on whether the ARN represents an access point or a multi-region access point.

sources[].type

Indicates the type of access that generated the finding.

status

The preview status of the finding. This is what the status of the finding would be after permissions deployment. For example, a Changed finding with preview status Resolved and existing status Active indicates the existing Active finding would become Resolved as a result of the proposed permissions change.

VARCHAR