Soumya Sivasankar, Chief Executive Officer at SupportSagesAbhilash Padmanabhan, Chief Technology Officer at SupportSages

Our leadership team is attending CloudFest Americas, from Nov 4 to 16. Schedule a Connect

Our Leadership team is attending CloudFest Americas 2026, from Nov 4 to 16.

Meet us in Miami to discuss MSP growth, DevOps excellence, and Cloud Transformation. Available for 1:1 meetings, Schedule a Connect

CloudFest logo
  • DevOps
    Case Study

    How we helped a development company rebuild DevOps for efficiency and scale.

    READ CASESTUDY
    icon

    24/7 DevOps as a Service

    Round-the-clock DevOps for uninterrupted efficiency.

    icon

    Infrastructure as a Code

    Crafting infrastructure with ingenious code.

    icon

    CI/CD Pipeline

    Automated CI/CD pipeline for seamless deployments.

    icon

    DevSecOps

    Integrated security in continuous DevOps practices.

    icon

    Hire DevOps Engineers

    Level up your team with DevOps visionaries.

    icon

    Consulting Services

    Navigate success with expert DevOps consulting.

  • TechOps
    Case Study

    How a US hosting leader scaled with us!

    READ CASESTUDY

    WEB HOSTING SUPPORT

    icon

    HelpDesk Support

    Highly skilled 24/7 HelpDesk Support

    icon

    Product Support

    Boost your product support with our expertise.

    MANAGED SERVICES

    icon

    Server Management

    Don’t let server issues slow you down. Let us manage them for you.

    icon

    Server Monitoring

    Safeguard your server health with our comprehensive monitoring solutions.

    STAFF AUGMENTATION

    icon

    Hire an Admin

    Transform your business operations with our expert administrative support.

    icon

    Hire a Team

    Augment your workforce with highly skilled professionals from our diverse talent pool.

  • CloudOps
    Case Study

    How we helped a Private Deemed University in India, save US $3500/m on hosting charges!

    READ CASESTUDY
    icon

    CloudOps as a Service

    24/7 monitoring, incident response, and cost-optimized cloud operations

    icon

    AWS Well Architected Review

    Round-the-clock for uninterrupted efficiency

    icon

    Optimize

    Efficient CloudOps mastery for seamless cloud management

    icon

    Manage

    Simplify compliance complexities with our dedicated service

    icon

    Migrate

    Upgrade the journey, Migrate & Modernize seamlessly

    icon

    Modernize

    Simplify compliance complexities with our dedicated services

  • SecOps
    Case Study

    Enabling financial grade platforms through strategic cloud modernisation.

    READ CASESTUDY
    icon

    VAPT

    Vulnerability Assessment and Penetration Testing

    icon

    Source Code Review

    Ensuring source code security ans safe practices to reduce risks

    icon

    Security Consultation

    On demand services for improving server security

    icon

    System Hardening

    Reduced vulnerability and proactive protection

    icon

    Managed SoC

    Monitors and maintains system security. Quick response on incidents.

    icon

    Compliance as a Service

    Regulatory compliance, reduced risk

  • K8s
  • Insights
    Case Study

    How we helped a Private Deemed University in India, save US $3,500/m on hosting charges!

    READ CASESTUDY
    icon

    Blog

    Explore our latest articles and insights

    icon

    Case Studies

    Read about our client success stories

    icon

    Flipbook

    Explore our latest Flipbook

    icon

    Events

    Join us at upcoming events and conferences

    icon

    Webinars

    Watch our educational webinar series

  • Contact Us

Interested to collaborate?

Get in touch with us!

Contact us today to learn how our team can help you leverage our managed cloud and DevOps services so you can focus on growing your business.

  • White Label Managed IT Services for MSPs
  • White Label MSP Support Services
  • Managed HelpDesk Services
  • White Label Maintenance Services for WordPress
  • Outsourced WebHosting Support
  • Hosting HelpDesk Support Services
  • cPanel Server Management
  • Plesk Server Management
  • DevOps Automation Services
  • DevOps Containerization Services
  • DevOps Engineering Services Experts
  • DevOps Maturity Assessment
  • DevOps Testing Services & Automation
  • DevOps Implementation Services
  • DevOps Transformation Services
  • White Label Kubernetes IT Services
  • Cloud Automation Services
  • Cloud Modernization Services
  • Database Migration Services
  • DevOps Outsourcing Services

AWS

  • AWS DevOps Services for Scalable Cloud
  • AWS Well-Architected Review
  • AWS Migration Services

Azure

  • Azure DevOps Services & Automation
  • Azure Migration Services

Google Cloud

  • Google Cloud Managed Services
  • Google Cloud Migration Services
  • Google Cloud Platform Services
  • AWSAWS
  • Azure CloudAzure Cloud
  • Google CloudGoogle Cloud
  • Akamai CloudAkamai Cloud
  • OVHOVH
  • Digital OceanDigital Ocean
  • HetznerHetzner
  • CloudOps as a Service
  • FinOps as a Service
  • Managed DigitalOcean Cloud
  • Managed OVH Cloud
  • Managed Hetzner Cloud
  • Managed Akamai Cloud
  • Oracle Managed Services
  • Our story
  • Life@SupportSages
  • Insights
  • Careers
  • Events
  • Contact Us
  • Sitemap

AWS Partner

AWS Advanced Tier Services PartnerAWS Well-Architected PartnerAWS Partner DevOps ServicesAWS Public Sector Partner40+ AWS Certified Engineers

Compliance

ISO 27001 certifiedGDPR compliant
LinkedInFacebookXInstagramYouTube
SupportSages

Copyright © 2008 - 2026 SupportSages Pvt Ltd. All Rights Reserved.
Privacy PolicyLegal TermsData ProtectionCookie Policy

Automating IAM user Audit Using Python.

Author Profile
Admin
  • 3 min read
Automating IAM user Audit Using Python.

Generating audio, please wait...

IAM user is an easy way of giving access to our colleagues or someone in our organization to get into our AWS account with limited or full privileges. We are all following the same IAM user method in many of our organizations and it is easy to maintain and add or revoke permissions with the help of AWS.

But there comes a scenario where the members relieved from the company get access to our AWS accounts right in their pocket. In order to solve this issue we need to conduct an IAM review over a frequent interval.

Let me say reviewing and Auditing for such things are pretty boring and time-consuming when it comes to AWS accounts with more users. This includes creating a list of users who haven't accessed the console for more than a particular amount of days and that should include details like whether they have console access or not, do they have active access keys, and if yes when they last accessed it, etc.

In order to overcome this time-consuming and boring process of creating an audit document for IAM I made a Python script that will do the job for us.

The script will do the following things.

Promotional banner

  1. Communicate with AWS using Boto3.
  2. List all the IAM users.
  3. Check for their last accessed date based on the user input(minimum age of users).
  4. Check whether the user has console access or not.
  5. If they have console access the script will tell us that they last accessed the console N number of days before.
  6. Check whether they have active IAM Access keys.
  7. If they have active Access keys the script will tell us that they accessed the Access keys N number of days before.
  8. The script finally generates a document namely “IAM-Audit-Report.txt”.

The output of the script which looks for a minimum age of users above 100 will look like this

1_y4gPWT8mMAxVQFm95KS5PA (1).webp

The script is given below.

import boto3
from datetime import datetime

now = datetime.utcnow()

iam = boto3.client('iam')

list_of_users = iam.list_users()

day_threshold = int(input("Please enter the preferred min age of users: "))

file_name = open("IAM-Audit-Report.txt" , "w")
def consoleaccess(name):
if 'PasswordLastUsed' in name:
ConsoleAccess = True
C1 = "yes"
last_used = (now - (name['PasswordLastUsed']).replace(tzinfo=None)).days
else:
ConsoleAccess = False
C1 = "no"
last_used = 0 # Set to 0 if no console access

return C1, last_used

def accesskey(access_keys, user_name):
num_keys = len(access_keys)
if num_keys == 0:
num_keys_str = "0"
last_key_accessed = "N/A"
else:
num_keys_str = str(num_keys)
last_key_accessed = "N/A"
for a_key in access_keys:
access_key_id = a_key['AccessKeyId']
if a_key['Status'] == 'Active':
last_access_key_used = iam.get_access_key_last_used(AccessKeyId=access_key_id)
if 'LastUsedDate' in last_access_key_used['AccessKeyLastUsed']:
date_of_access = (last_access_key_used['AccessKeyLastUsed']['LastUsedDate']).replace(tzinfo=None)
days_of_access = (now - date_of_access).days
if last_key_accessed == "N/A" or days_of_access < last_key_accessed:
last_key_accessed = days_of_access
if last_key_accessed == "N/A":
last_key_accessed = "N/A"
else:
last_key_accessed = str(last_key_accessed)

return num_keys_str, last_key_accessed

for name in list_of_users['Users']:
user_name = name['UserName']
arn = name['Arn']
access_keys = iam.list_access_keys(UserName=user_name)['AccessKeyMetadata']
C1, last_used = consoleaccess(name)
num_keys_str, last_key_accessed = accesskey(access_keys, user_name)

if last_used > day_threshold:
file_name.write(f"User: {user_name}\nArn: {arn}\nConsole Access: {C1}\nLast Console Access: {last_used} days before\nNumber of Access Keys: {num_keys_str}\nLast Access Key Accessed: {last_key_accessed} or never used before\n\n")
print("Your report is ready")
file_name.close()

That’s all Thank you ❤

Discover streamlined AWS IAM auditing! Simplify the user access review process with our Python script, generating comprehensive reports effortlessly. Explore SupportSages for expert insights on enhancing AWS account security.

  • AWS
  • DevOps
  • Security

Continue Your Journey With…

DevOps as a Service

DevOps as a Service

Let us do the heavy lifting for you

Security Consultation

Security Consultation

In today's dynamic digital landscape, our professional security consultation services help optimize your business by strengthening defenses and identifying vulnerabilities.

System Hardening

Reduce attack surface with hardened OS, network, and cloud configurations tailored to your environment.

Promotional banner
Promotional banner

5 Things You Should Know About AWS Well-Architected Framework Review

5 Things You Should Know About AWS Well-Architected Framework Review
  • AWS
  • Cloud Optimisation
  • Security
  • FinOps
logo

Automate AWS SSM Parameter Store Backups with Python and Boto3

Automate AWS SSM Parameter Store Backups with Python and Boto3
  • AWS
  • DevOps
  • Backup management
logo

Create new user account in Argo CD with Read Only Access

Create new user account in Argo CD with Read Only Access
  • AWS
  • DevOps
  • Kubernetes
  • Security
logo

Effortless S3 Bucket Access Log Activation Across Your AWS Account with Python Automation

Effortless S3 Bucket Access Log Activation Across Your AWS Account with Python Automation
  • AWS
  • DevOps
  • Security
  • Cloud Monitoring
logo

Posts by Admin