こんにちは、小寺です。
IAM Access Analyzerが200を超えるサービスをサポートしました。

https://aws.amazon.com/about-aws/whats-new/2023/11/iam-access-analyzer-policy-generation-coverage-over-200-aws-services/

IAM Access Analizerとは

AWS Identity and Access Management (IAM) Access Analyzerは、最小権限アクセスを実現するためのサービスです。
AWSリソースに紐付いているポリシーを検査し、他AWSアカウントや外部のインターネット等からのアクセスを可能とするような設定がされているかどうか、”意図せぬ公開設定がされていないか”を検出および可視化してくれるサービスです。

・きめ細やかな設定の許可
CloudTrail の履歴をベースにしたポリシー生成で、100 種類以上のポリシーチェックにより、安全で機能的なポリシーを作成、検証することができます。

・意図的な許可の検証
パブリックおよびクロスアカウントを検証することにより、AM Access Analyzer をオンにすると、新規または更新されたリソースのアクセス許可を継続的にモニタリングして、パブリックアクセスおよびクロスアカウントアクセスを許可するポリシーの特定ができます。
利用されているアカウントの外側からの意図しないアクセスからリソースが保護されているかどうか確認が可能です。

・未使用のアクセスを削除して許可設定を改善
AWS のサービスが最後に使用された日時の確認が可能です。付与されたアクセスポリシーとそれらのポリシーが最後にアクセスされたタイミングを確認することができるので、使われていないポリシーの削除が可能です。

有効にするには、こちらから。

アップデート内容

200 を超える AWS サービスアクションがサポートされるようになり、AWS CloudTrail アクセス アクティビティに基づいて詳細なポリシーを作成できるようになっています。
新しく追加されたサービスには、Auto Scaling、Amazon Redshift、Amazon Route 53 などが含まれます。

以下のサービスに対応済みです。

ServiceService prefix
AWS Identity and Access Management Access Analyzeraccess-analyzer
AWS Account Managementaccount
AWS Certificate Manageracm
Amazon Managed Workflows for Apache Airflowairflow
AWS Amplifyamplify
AWS Amplify UI Builderamplifyuibuilder
Amazon AppIntegrationsapp-integrations
AWS AppConfigappconfig
Amazon AppFlowappflow
AWS Application Cost Profilerapplication-cost-profiler
Amazon CloudWatch Application Insightsapplicationinsights
AWS App Meshappmesh
Amazon AppStream 2.0appstream
AWS AppSyncappsync
Amazon Managed Service for Prometheusaps
Amazon Athenaathena
AWS Audit Managerauditmanager
AWS Auto Scalingautoscaling
AWS Marketplaceaws-marketplace
AWS Backupbackup
AWS Batchbatch
Amazon Braketbraket
AWS Budgetsbudgets
AWS Cloud9cloud9
AWS CloudFormationcloudformation
Amazon CloudFrontcloudfront
AWS CloudHSMcloudhsm
Amazon CloudSearchcloudsearch
AWS CloudTrailcloudtrail
Amazon CloudWatchcloudwatch
AWS CodeArtifactcodeartifact
AWS CodeDeploycodedeploy
Amazon CodeGuru Profilercodeguru-profiler
Amazon CodeGuru Reviewercodeguru-reviewer
AWS CodePipelinecodepipeline
AWS CodeStarcodestar
AWS CodeStar Notificationscodestar-notifications
Amazon Cognito Identitycognito-identity
Amazon Cognito user poolscognito-idp
Amazon Cognito Synccognito-sync
Amazon Comprehend Medicalcomprehendmedical
AWS Compute Optimizercompute-optimizer
AWS Configconfig
Amazon Connectconnect
AWS Cost and Usage Reportcur
AWS Glue DataBrewdatabrew
AWS Data Exchangedataexchange
AWS Data Pipelinedatapipeline
DynamoDB Acceleratordax
AWS Device Farmdevicefarm
Amazon DevOps Gurudevops-guru
AWS Direct Connectdirectconnect
Amazon Data Lifecycle Managerdlm
AWS Database Migration Servicedms
Amazon DocumentDB Elastic Clustersdocdb-elastic
AWS Directory Serviceds
Amazon DynamoDBdynamodb
Amazon Elastic Block Storeebs
Amazon Elastic Compute Cloudec2
Amazon Elastic Container Registryecr
Amazon Elastic Container Registry Publicecr-public
Amazon Elastic Container Serviceecs
Amazon Elastic Kubernetes Serviceeks
Amazon Elastic Inferenceelastic-inference
Amazon ElastiCacheelasticache
AWS Elastic Beanstalkelasticbeanstalk
Amazon Elastic File Systemelasticfilesystem
Elastic Load Balancingelasticloadbalancing
Amazon Elastic Transcoderelastictranscoder
Amazon EMR on EKS (EMR Containers)emr-containers
Amazon EMR Serverlessemr-serverless
Amazon OpenSearch Servicees
Amazon EventBridgeevents
Amazon CloudWatch Evidentlyevidently
Amazon FinSpacefinspace
Amazon Kinesis Data Firehosefirehose
AWS Fault Injection Simulatorfis
AWS Firewall Managerfms
Amazon Fraud Detectorfrauddetector
Amazon FSxfsx
Amazon GameLiftgamelift
Amazon Location Servicegeo
Amazon S3 Glacierglacier
Amazon Managed Grafanagrafana
AWS IoT Greengrassgreengrass
AWS Ground Stationgroundstation
Amazon GuardDutyguardduty
AWS HealthLakehealthlake
Amazon Honeycodehoneycode
AWS Identity and Access Managementiam
AWS Identity Storeidentitystore
EC2 Image Builderimagebuilder
Amazon Inspector Classicinspector
Amazon Inspectorinspector2
AWS IoTiot
AWS IoT Analyticsiotanalytics
AWS IoT Core Device Advisoriotdeviceadvisor
AWS IoT Eventsiotevents
AWS IoT Fleet Hubiotfleethub
AWS IoT SiteWiseiotsitewise
AWS IoT TwinMakeriottwinmaker
AWS IoT Wirelessiotwireless
Amazon Interactive Video Serviceivs
Amazon Interactive Video Service Chativschat
Amazon Managed Streaming for Apache Kafkakafka
Amazon Managed Streaming for Kafka Connectkafkaconnect
Amazon Kendrakendra
Amazon Kinesiskinesis
Amazon Kinesis Analytics V2kinesisanalytics
AWS Key Management Servicekms
AWS Lambdalambda
Amazon Lexlex
AWS License Manager Linux Subscriptions Managerlicense-manager-linux-subscriptions
Amazon Lightsaillightsail
Amazon CloudWatch Logslogs
Amazon Lookout for Equipmentlookoutequipment
Amazon Lookout for Metricslookoutmetrics
Amazon Lookout for Visionlookoutvision
AWS Mainframe Modernizationm2
Amazon Managed Blockchainmanagedblockchain
AWS Elemental MediaConnectmediaconnect
AWS Elemental MediaConvertmediaconvert
AWS Elemental MediaLivemedialive
AWS Elemental MediaPackagemediapackage
AWS Elemental MediaPackage VODmediapackage-vod
AWS Elemental MediaStoremediastore
AWS Elemental MediaTailormediatailor
Amazon MemoryDB for Redismemorydb
AWS Application Migration Servicemgn
AWS Migration Hubmgh
AWS Migration Hub Strategy Recommendationsmigrationhub-strategy
Amazon Pinpointmobiletargeting
Amazon MQmq
AWS Network Managernetworkmanager
Amazon Nimble Studionimble
AWS HealthOmicsomics
AWS OpsWorksopsworks
AWS OpsWorks CMopsworks-cm
AWS Outpostsoutposts
AWS Organizationsorganizations
AWS Panoramapanorama
AWS Performance Insightspi
Amazon EventBridge Pipespipes
Amazon Pollypolly
Amazon Connect Customer Profilesprofile
Amazon QLDBqldb
AWS Resource Access Managerram
AWS Recycle Binrbin
Amazon Relational Database Servicerds
Amazon Redshiftredshift
Amazon Redshift Data APIredshift-data
AWS Migration Hub Refactor Spacesrefactor-spaces
Amazon Rekognitionrekognition
AWS Resilience Hubresiliencehub
AWS Resource Explorerresource-explorer-2
AWS Resource Groupsresource-groups
AWS RoboMakerrobomaker
AWS Identity and Access Management Roles Anywhererolesanywhere
Amazon Route 53route53
Amazon Route 53 Recovery Controlsroute53-recovery-control-config
Amazon Route 53 Recovery Readinessroute53-recovery-readiness
Amazon Route 53 Resolverroute53resolver
AWS CloudWatch RUMrum
Amazon Simple Storage Services3
Amazon S3 on Outpostss3-outposts
Amazon SageMaker geospatial capabilitiessagemaker-geospatial
Savings Planssavingsplans
Amazon EventBridge Schemasschemas
Amazon SimpleDBsdb
AWS Secrets Managersecretsmanager
AWS Security Hubsecurityhub
Amazon Security Lakesecuritylake
AWS Serverless Application Repositoryserverlessrepo
AWS Service Catalogservicecatalog
AWS Cloud Mapservicediscovery
Service Quotasservicequotas
Amazon Simple Email Serviceses
AWS Shieldshield
AWS Signersigner
AWS SimSpace Weaversimspaceweaver
AWS Server Migration Servicesms
Amazon Pinpoint SMS and Voice Servicesms-voice
AWS Snowballsnowball
Amazon Simple Queue Servicesqs
AWS Systems Managerssm
AWS Systems Manager Incident Managerssm-incidents
AWS Systems Manager for SAPssm-sap
AWS Step Functionsstates
AWS Security Token Servicests
Amazon Simple Workflow Serviceswf
Amazon CloudWatch Syntheticssynthetics
AWS Resource Groups Tagging APItag
Amazon Textracttextract
Amazon Timestreamtimestream
AWS Telco Network Buildertnb
Amazon Transcribetranscribe
AWS Transfer Familytransfer
Amazon Translatetranslate
Amazon Connect Voice IDvoiceid
Amazon VPC Latticevpc-lattice
AWS WAFV2wafv2
AWS Well-Architected Toolwellarchitected
Amazon Connect Wisdomwisdom
Amazon WorkLinkworklink
Amazon WorkSpacesworkspaces
AWS X-Rayxray