Skip to main content
With untrusted external access findings, you can treat unexpected third-party access as a security issue and work it like any other finding. When a resource grants access to a principal outside your AWS organization that you have not confirmed as trusted, Plerion raises a finding so the access shows up in your normal triage.
Expect a large number of findings on the first scan. Plerion raises one for every asset that grants access to an external principal you have not confirmed, and a new tenant starts with almost nothing on its trusted principals list. Most of that first wave is usually access you meant to grant.Work through trusted principals before working through the findings one by one. A single entry clears every grant that principal holds, across every resource it touches, so the count usually falls sharply on the next scan.

How untrusted access becomes a finding

Plerion evaluates every grant in the resource access grants inventory. When a resource has one or more grants to an Untrusted external principal, Plerion:
  • Sets the Grants external access context on the affected asset.
  • Raises a finding against that asset.
There is one finding per asset, covering every external grant on it. Once every one of those grants is trusted, the finding stops failing and becomes informational on the next scan: it stays on record as the account of who has access, with no severity to act on. Trusting one principal only stops the finding failing if it was the last untrusted grant on that asset, and a grant Plerion has not classified yet counts as not trusted for this purpose. A finding can also start failing again on its own. If someone widens a grant that a reviewer had trusted until its review date, that trust ends early, the grant shows Needs re-review, and the finding fails until the grant is reviewed again.

Severity

Untrusted external access findings carry a severity level like any other finding, so you can prioritize them alongside the rest of your posture. Plerion rates each finding from the access the grant actually allows:
  • A grant that allows broad or destructive actions scores higher than one limited to reading.
  • Access to a resource holding classified data, or to a role that carries administrative or privilege-escalation rights, raises the score further.
  • Conditions that restrict when the grant applies lower it.
Because the principal is untrusted, Plerion also treats the access as more likely to be a genuine exposure. When an asset has more than one untrusted grant, the finding takes the highest severity among them. See Findings for what each severity level means.
Untrusted external access findings are rated Low, Medium, or High. A grant is access someone still has to use, so no amount of scoring takes one of these findings to Critical.

Finding untrusted external access

1

Open the Findings dashboard

2

Filter by asset context

In the filter panel, set Asset context to Grants external access to show only the assets that grant external access.
Findings dashboard filtered to the Grants external access asset context

Understanding the finding detail

Select a finding to open its detail view. Alongside the standard finding summary, remediation guidance, and primary asset, the Overview shows an external access graph for the asset. The graph maps each external principal that holds a grant and labels it with its trust status, so you can see at a glance which principals are Untrusted, Trusted, or Unclassified.
Finding detail showing the external access graph with principal trust status

The Access grants tab

The finding also carries an Access grants tab listing every principal that holds a grant on the asset, untrusted ones first. Each row shows the principal, its type, its AWS account, the access it has, and its trust status. Select Trust this principal on a row to add that principal to the trusted principals list of the profile that applies to the asset’s integration. Its grants stop being flagged once the next scan re-evaluates them. The button is not offered for principals that cannot be expressed as a trust entry, such as a wildcard (*) principal, and it is hidden if you do not have permission to edit trusted principals.
Access grants tab on a finding listing each principal with its trust status and a Trust this principal button
To see the exact actions and conditions behind a grant, open the matching row in the resource access grants inventory and use its Permissions and Policy tabs.

Resolving a finding

Exemptions do not apply to untrusted external access findings, and the Exempt action is disabled on them. Each external grant is meant to be confirmed on the finding itself so the access stays on record, rather than being exempted out of sight. Use one of the three routes below.
  • Trust the principal is the primary route. Add it from the finding’s Access grants tab, or from the trusted principals tab of the profile.
  • Trust until review is a review decision recorded on the grant itself. It stops counting toward the finding until the review date you set, then returns to the queue.
  • Remove or restrict the access means changing the resource policy or trust policy in AWS to drop the principal or tighten its conditions.
Whichever you choose, the finding updates on the next scan.