@ThreadSafe @Generated(value="com.amazonaws:aws-java-sdk-code-generator") public class AWSAccessAnalyzerClient extends AmazonWebServiceClient implements AWSAccessAnalyzer
Identity and Access Management Access Analyzer helps identify potential resource-access risks by enabling you to identify any policies that grant access to an external principal. It does this by using logic-based reasoning to analyze resource-based policies in your Amazon Web Services environment. An external principal can be another Amazon Web Services account, a root user, an IAM user or role, a federated user, an Amazon Web Services service, or an anonymous user. You can also use IAM Access Analyzer to preview and validate public and cross-account access to your resources before deploying permissions changes. This guide describes the Identity and Access Management Access Analyzer operations that you can call programmatically. For general information about IAM Access Analyzer, see Identity and Access Management Access Analyzer in the IAM User Guide.
To start using IAM Access Analyzer, you first need to create an analyzer.
LOGGING_AWS_REQUEST_METRIC
ENDPOINT_PREFIX
Modifier and Type | Method and Description |
---|---|
ApplyArchiveRuleResult |
applyArchiveRule(ApplyArchiveRuleRequest request)
Retroactively applies the archive rule to existing findings that meet the archive rule criteria.
|
static AWSAccessAnalyzerClientBuilder |
builder() |
CancelPolicyGenerationResult |
cancelPolicyGeneration(CancelPolicyGenerationRequest request)
Cancels the requested policy generation.
|
CreateAccessPreviewResult |
createAccessPreview(CreateAccessPreviewRequest request)
Creates an access preview that allows you to preview IAM Access Analyzer findings for your resource before
deploying resource permissions.
|
CreateAnalyzerResult |
createAnalyzer(CreateAnalyzerRequest request)
Creates an analyzer for your account.
|
CreateArchiveRuleResult |
createArchiveRule(CreateArchiveRuleRequest request)
Creates an archive rule for the specified analyzer.
|
DeleteAnalyzerResult |
deleteAnalyzer(DeleteAnalyzerRequest request)
Deletes the specified analyzer.
|
DeleteArchiveRuleResult |
deleteArchiveRule(DeleteArchiveRuleRequest request)
Deletes the specified archive rule.
|
GetAccessPreviewResult |
getAccessPreview(GetAccessPreviewRequest request)
Retrieves information about an access preview for the specified analyzer.
|
GetAnalyzedResourceResult |
getAnalyzedResource(GetAnalyzedResourceRequest request)
Retrieves information about a resource that was analyzed.
|
GetAnalyzerResult |
getAnalyzer(GetAnalyzerRequest request)
Retrieves information about the specified analyzer.
|
GetArchiveRuleResult |
getArchiveRule(GetArchiveRuleRequest request)
Retrieves information about an archive rule.
|
ResponseMetadata |
getCachedResponseMetadata(AmazonWebServiceRequest request)
Returns additional metadata for a previously executed successful, request, typically used for debugging issues
where a service isn't acting as expected.
|
GetFindingResult |
getFinding(GetFindingRequest request)
Retrieves information about the specified finding.
|
GetGeneratedPolicyResult |
getGeneratedPolicy(GetGeneratedPolicyRequest request)
Retrieves the policy that was generated using
StartPolicyGeneration . |
ListAccessPreviewFindingsResult |
listAccessPreviewFindings(ListAccessPreviewFindingsRequest request)
Retrieves a list of access preview findings generated by the specified access preview.
|
ListAccessPreviewsResult |
listAccessPreviews(ListAccessPreviewsRequest request)
Retrieves a list of access previews for the specified analyzer.
|
ListAnalyzedResourcesResult |
listAnalyzedResources(ListAnalyzedResourcesRequest request)
Retrieves a list of resources of the specified type that have been analyzed by the specified analyzer..
|
ListAnalyzersResult |
listAnalyzers(ListAnalyzersRequest request)
Retrieves a list of analyzers.
|
ListArchiveRulesResult |
listArchiveRules(ListArchiveRulesRequest request)
Retrieves a list of archive rules created for the specified analyzer.
|
ListFindingsResult |
listFindings(ListFindingsRequest request)
Retrieves a list of findings generated by the specified analyzer.
|
ListPolicyGenerationsResult |
listPolicyGenerations(ListPolicyGenerationsRequest request)
Lists all of the policy generations requested in the last seven days.
|
ListTagsForResourceResult |
listTagsForResource(ListTagsForResourceRequest request)
Retrieves a list of tags applied to the specified resource.
|
void |
shutdown()
Shuts down this client object, releasing any resources that might be held
open.
|
StartPolicyGenerationResult |
startPolicyGeneration(StartPolicyGenerationRequest request)
Starts the policy generation request.
|
StartResourceScanResult |
startResourceScan(StartResourceScanRequest request)
Immediately starts a scan of the policies applied to the specified resource.
|
TagResourceResult |
tagResource(TagResourceRequest request)
Adds a tag to the specified resource.
|
UntagResourceResult |
untagResource(UntagResourceRequest request)
Removes a tag from the specified resource.
|
UpdateArchiveRuleResult |
updateArchiveRule(UpdateArchiveRuleRequest request)
Updates the criteria and values for the specified archive rule.
|
UpdateFindingsResult |
updateFindings(UpdateFindingsRequest request)
Updates the status for the specified findings.
|
ValidatePolicyResult |
validatePolicy(ValidatePolicyRequest request)
Requests the validation of a policy and returns a list of findings.
|
addRequestHandler, addRequestHandler, configureRegion, getClientConfiguration, getEndpointPrefix, getMonitoringListeners, getRequestMetricsCollector, getServiceName, getSignerByURI, getSignerOverride, getSignerRegionOverride, getTimeOffset, makeImmutable, removeRequestHandler, removeRequestHandler, setEndpoint, setEndpoint, setRegion, setServiceNameIntern, setSignerRegionOverride, setTimeOffset, withEndpoint, withRegion, withRegion, withTimeOffset
public static AWSAccessAnalyzerClientBuilder builder()
public ApplyArchiveRuleResult applyArchiveRule(ApplyArchiveRuleRequest request)
Retroactively applies the archive rule to existing findings that meet the archive rule criteria.
applyArchiveRule
in interface AWSAccessAnalyzer
applyArchiveRuleRequest
- Retroactively applies an archive rule.ResourceNotFoundException
- The specified resource could not be found.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public CancelPolicyGenerationResult cancelPolicyGeneration(CancelPolicyGenerationRequest request)
Cancels the requested policy generation.
cancelPolicyGeneration
in interface AWSAccessAnalyzer
cancelPolicyGenerationRequest
- ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public CreateAccessPreviewResult createAccessPreview(CreateAccessPreviewRequest request)
Creates an access preview that allows you to preview IAM Access Analyzer findings for your resource before deploying resource permissions.
createAccessPreview
in interface AWSAccessAnalyzer
createAccessPreviewRequest
- ResourceNotFoundException
- The specified resource could not be found.ConflictException
- A conflict exception error.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ServiceQuotaExceededException
- Service quote met error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public CreateAnalyzerResult createAnalyzer(CreateAnalyzerRequest request)
Creates an analyzer for your account.
createAnalyzer
in interface AWSAccessAnalyzer
createAnalyzerRequest
- Creates an analyzer.ConflictException
- A conflict exception error.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ServiceQuotaExceededException
- Service quote met error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public CreateArchiveRuleResult createArchiveRule(CreateArchiveRuleRequest request)
Creates an archive rule for the specified analyzer. Archive rules automatically archive new findings that meet the criteria you define when you create the rule.
To learn about filter keys that you can use to create an archive rule, see IAM Access Analyzer filter keys in the IAM User Guide.
createArchiveRule
in interface AWSAccessAnalyzer
createArchiveRuleRequest
- Creates an archive rule.ResourceNotFoundException
- The specified resource could not be found.ConflictException
- A conflict exception error.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ServiceQuotaExceededException
- Service quote met error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public DeleteAnalyzerResult deleteAnalyzer(DeleteAnalyzerRequest request)
Deletes the specified analyzer. When you delete an analyzer, IAM Access Analyzer is disabled for the account or organization in the current or specific Region. All findings that were generated by the analyzer are deleted. You cannot undo this action.
deleteAnalyzer
in interface AWSAccessAnalyzer
deleteAnalyzerRequest
- Deletes an analyzer.ResourceNotFoundException
- The specified resource could not be found.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public DeleteArchiveRuleResult deleteArchiveRule(DeleteArchiveRuleRequest request)
Deletes the specified archive rule.
deleteArchiveRule
in interface AWSAccessAnalyzer
deleteArchiveRuleRequest
- Deletes an archive rule.ResourceNotFoundException
- The specified resource could not be found.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public GetAccessPreviewResult getAccessPreview(GetAccessPreviewRequest request)
Retrieves information about an access preview for the specified analyzer.
getAccessPreview
in interface AWSAccessAnalyzer
getAccessPreviewRequest
- ResourceNotFoundException
- The specified resource could not be found.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public GetAnalyzedResourceResult getAnalyzedResource(GetAnalyzedResourceRequest request)
Retrieves information about a resource that was analyzed.
getAnalyzedResource
in interface AWSAccessAnalyzer
getAnalyzedResourceRequest
- Retrieves an analyzed resource.ResourceNotFoundException
- The specified resource could not be found.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public GetAnalyzerResult getAnalyzer(GetAnalyzerRequest request)
Retrieves information about the specified analyzer.
getAnalyzer
in interface AWSAccessAnalyzer
getAnalyzerRequest
- Retrieves an analyzer.ResourceNotFoundException
- The specified resource could not be found.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public GetArchiveRuleResult getArchiveRule(GetArchiveRuleRequest request)
Retrieves information about an archive rule.
To learn about filter keys that you can use to create an archive rule, see IAM Access Analyzer filter keys in the IAM User Guide.
getArchiveRule
in interface AWSAccessAnalyzer
getArchiveRuleRequest
- Retrieves an archive rule.ResourceNotFoundException
- The specified resource could not be found.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public GetFindingResult getFinding(GetFindingRequest request)
Retrieves information about the specified finding.
getFinding
in interface AWSAccessAnalyzer
getFindingRequest
- Retrieves a finding.ResourceNotFoundException
- The specified resource could not be found.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public GetGeneratedPolicyResult getGeneratedPolicy(GetGeneratedPolicyRequest request)
Retrieves the policy that was generated using StartPolicyGeneration
.
getGeneratedPolicy
in interface AWSAccessAnalyzer
getGeneratedPolicyRequest
- ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public ListAccessPreviewFindingsResult listAccessPreviewFindings(ListAccessPreviewFindingsRequest request)
Retrieves a list of access preview findings generated by the specified access preview.
listAccessPreviewFindings
in interface AWSAccessAnalyzer
listAccessPreviewFindingsRequest
- ResourceNotFoundException
- The specified resource could not be found.ConflictException
- A conflict exception error.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public ListAccessPreviewsResult listAccessPreviews(ListAccessPreviewsRequest request)
Retrieves a list of access previews for the specified analyzer.
listAccessPreviews
in interface AWSAccessAnalyzer
listAccessPreviewsRequest
- ResourceNotFoundException
- The specified resource could not be found.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public ListAnalyzedResourcesResult listAnalyzedResources(ListAnalyzedResourcesRequest request)
Retrieves a list of resources of the specified type that have been analyzed by the specified analyzer..
listAnalyzedResources
in interface AWSAccessAnalyzer
listAnalyzedResourcesRequest
- Retrieves a list of resources that have been analyzed.ResourceNotFoundException
- The specified resource could not be found.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public ListAnalyzersResult listAnalyzers(ListAnalyzersRequest request)
Retrieves a list of analyzers.
listAnalyzers
in interface AWSAccessAnalyzer
listAnalyzersRequest
- Retrieves a list of analyzers.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public ListArchiveRulesResult listArchiveRules(ListArchiveRulesRequest request)
Retrieves a list of archive rules created for the specified analyzer.
listArchiveRules
in interface AWSAccessAnalyzer
listArchiveRulesRequest
- Retrieves a list of archive rules created for the specified analyzer.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public ListFindingsResult listFindings(ListFindingsRequest request)
Retrieves a list of findings generated by the specified analyzer.
To learn about filter keys that you can use to retrieve a list of findings, see IAM Access Analyzer filter keys in the IAM User Guide.
listFindings
in interface AWSAccessAnalyzer
listFindingsRequest
- Retrieves a list of findings generated by the specified analyzer.ResourceNotFoundException
- The specified resource could not be found.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public ListPolicyGenerationsResult listPolicyGenerations(ListPolicyGenerationsRequest request)
Lists all of the policy generations requested in the last seven days.
listPolicyGenerations
in interface AWSAccessAnalyzer
listPolicyGenerationsRequest
- ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public ListTagsForResourceResult listTagsForResource(ListTagsForResourceRequest request)
Retrieves a list of tags applied to the specified resource.
listTagsForResource
in interface AWSAccessAnalyzer
listTagsForResourceRequest
- Retrieves a list of tags applied to the specified resource.ResourceNotFoundException
- The specified resource could not be found.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public StartPolicyGenerationResult startPolicyGeneration(StartPolicyGenerationRequest request)
Starts the policy generation request.
startPolicyGeneration
in interface AWSAccessAnalyzer
startPolicyGenerationRequest
- ConflictException
- A conflict exception error.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ServiceQuotaExceededException
- Service quote met error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public StartResourceScanResult startResourceScan(StartResourceScanRequest request)
Immediately starts a scan of the policies applied to the specified resource.
startResourceScan
in interface AWSAccessAnalyzer
startResourceScanRequest
- Starts a scan of the policies applied to the specified resource.ResourceNotFoundException
- The specified resource could not be found.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public TagResourceResult tagResource(TagResourceRequest request)
Adds a tag to the specified resource.
tagResource
in interface AWSAccessAnalyzer
tagResourceRequest
- Adds a tag to the specified resource.ResourceNotFoundException
- The specified resource could not be found.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public UntagResourceResult untagResource(UntagResourceRequest request)
Removes a tag from the specified resource.
untagResource
in interface AWSAccessAnalyzer
untagResourceRequest
- Removes a tag from the specified resource.ResourceNotFoundException
- The specified resource could not be found.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public UpdateArchiveRuleResult updateArchiveRule(UpdateArchiveRuleRequest request)
Updates the criteria and values for the specified archive rule.
updateArchiveRule
in interface AWSAccessAnalyzer
updateArchiveRuleRequest
- Updates the specified archive rule.ResourceNotFoundException
- The specified resource could not be found.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public UpdateFindingsResult updateFindings(UpdateFindingsRequest request)
Updates the status for the specified findings.
updateFindings
in interface AWSAccessAnalyzer
updateFindingsRequest
- Updates findings with the new values provided in the request.ResourceNotFoundException
- The specified resource could not be found.ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public ValidatePolicyResult validatePolicy(ValidatePolicyRequest request)
Requests the validation of a policy and returns a list of findings. The findings help you identify issues and provide actionable recommendations to resolve the issue and enable you to author functional policies that meet security best practices.
validatePolicy
in interface AWSAccessAnalyzer
validatePolicyRequest
- ValidationException
- Validation exception error.InternalServerException
- Internal server error.ThrottlingException
- Throttling limit exceeded error.AccessDeniedException
- You do not have sufficient access to perform this action.public ResponseMetadata getCachedResponseMetadata(AmazonWebServiceRequest request)
Response metadata is only cached for a limited period of time, so if you need to access this extra diagnostic information for an executed request, you should use this method to retrieve it as soon as possible after executing the request.
getCachedResponseMetadata
in interface AWSAccessAnalyzer
request
- The originally executed requestpublic void shutdown()
AmazonWebServiceClient
shutdown
in interface AWSAccessAnalyzer
shutdown
in class AmazonWebServiceClient