cmc/cleberg.net
My personal web garden & blog.
clone: git clone https://gitbay.org/cmc/cleberg.net.git
f3dc1cdc37ae0121bf2dcf1b54a31d23720e4e92
signed_unknown_key
author: Christian Cleberg <hello@cleberg.net> · 2026-02-22T04:03:56Z
committer: <noreply@github.com>
content/blog/2026-02-21-auditing-aws-iam.org | 2 +- content/blog/2026-02-21-auditing-aws-passwords.org | 4 ++++ 2 files changed, 5 insertions(+), 1 deletion(-) @@ -1,5 +1,5 @@ #+date: [2026-02-21 Sat 18:58:39] -#+title: Auditing AWS IAM Identity Center Assignments +#+title: Auditing AWS IAM Users #+description: Learn how to audit IAM user assignments in AWS. #+slug: auditing-aws-iam @@ -98,6 +98,10 @@ The metadata block is what ties this evidence to a specific account and point in time. The ~aws_caller_identity~ field shows who ran the script and in which account. +#+caption: Policy Evaluation Results +#+attr_html: :alt Terminal output of evaluate_policy.py showing the interactive prompts and pass/fail summary for each password policy rule. +[[https://img.cleberg.net/blog/20260221-auditing-aws-password-policy/results.webp]] + * Step 2: Evaluate the Policy Pass the JSON file to the evaluation script: