Control: AWS > Turbot > IAM > User > Managed
The control focuses on the Turbot-managed user accounts, this control updates and deletes user accounts based on their assignment status. It also applies necessary lockdown, boundary, and deny policies to user accounts, further tightening security. Additionally, it controls group memberships by removing users from groups that are associated outside of Turbot, depending on the policy AWS > Turbot > Permissions > User > Group Membership Mode
. This ensures that user access levels are consistently managed and aligned with the organization's access control policies.
Resource Types
This control targets the following resource types:
Policies
This control type relies on these other policies when running actions:
- AWS > Turbot > Permissions > Policy > Name Prefix
- AWS > Turbot > Permissions > Policy > Name Path
- AWS > Turbot > IAM > Managed
- AWS > Turbot > Permissions > Policy > Name Path
- AWS > Turbot > Permissions > Policy > Name Prefix
- AWS > Turbot > Permissions > Group > Name Path
- AWS > Turbot > Permissions > User > Name Path
- AWS > Turbot > Permissions > User > Tags
- AWS > Turbot > Permissions > User Boundary
- AWS > Turbot > Permissions > Superuser Boundary
- AWS > Turbot > Permissions > Custom Group Levels [Account]
- AWS > Turbot > Permissions > User > Group Membership Mode
- AWS > IAM > Login User Names
Permissions
Cloud permissions used by this control and its actions:
iam:DeactivateMFADevice
iam:DeleteAccessKey
iam:DeleteLoginProfile
iam:DeleteUser
iam:DeleteUserPolicy
iam:DeleteVirtualMFADevice
iam:DetachUserPolicy
iam:ListAccessKeys
iam:ListMFADevices
iam:RemoveUserFromGroup
iam:PutUserPermissionsBoundary
iam:DeleteUserPermissionsBoundary
iam:UntagUser
iam:TagUser
iam:AttachUserPolicy
iam:DetachUserPolicy
iam:RemoveUserFromGroup
Category
In Your Workspace
Developers
- tmod:@turbot/aws-iam#/control/types/iamTurbotUserManaged
- tmod:@turbot/turbot#/control/categories/iam
- turbot graphql controls --filter "controlTypeId:tmod:@turbot/aws-iam#/control/types/iamTurbotUserManaged"
Get Controls
Control Type URI
Category URI
GraphQL
CLI