Amazon Web Services configurationPolicyAssociation API

The configurationPolicyAssociation API from Amazon Web Services — 5 operation(s) for configurationpolicyassociation.

OpenAPI Specification

amazon-web-services-configurationpolicyassociation-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Amazon Web Services accessanalyzer 2012 09 25 configurationPolicyAssociation API
  description: <p>Identity and Access Management Access Analyzer helps you to set, verify, and refine your IAM policies by providing a suite of capabilities. Its features include findings for external and unused access, basic and custom policy checks for validating policies, and policy generation to generate fine-grained policies. To start using IAM Access Analyzer to identify external or unused access, you first need to create an analyzer.</p> <p> <b>External access analyzers</b> help identify potential risks of accessing resources by enabling you to identify any resource policies that grant access to an external principal. It does this by using logic-based reasoning to analyze resource-based policies in your Amazon Web Services environment. An external principal can be another Amazon Web Services account, a root user, an IAM user or role, a federated user, an Amazon Web Services service, or an anonymous user. You can also use IAM Access Analyzer to preview public and cross-account access to your resources before deploying permissions changes.</p> <p> <b>Unused access analyzers</b> help identify potential identity access risks by enabling you to identify unused IAM roles, unused access keys, unused console passwords, and IAM principals with unused service and action-level permissions.</p> <p>Beyond findings, IAM Access Analyzer provides basic and custom policy checks to validate IAM policies before deploying permissions changes. You can use policy generation to refine permissions by attaching a policy generated using access activity logged in CloudTrail logs. </p> <p>This guide describes the IAM Access Analyzer operations that you can call programmatically. For general information about IAM Access Analyzer, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html">Identity and Access Management Access Analyzer</a> in the <b>IAM User Guide</b>.</p>
tags:
- name: configurationPolicyAssociation
paths:
  /configurationPolicyAssociation/batchget:
    POST:
      summary: Amazon Web Services Batchgetconfigurationpolicyassociations
      description: ' Returns associations between an Security Hub configuration and a batch of target accounts, organizational units, or the root. Only the Security Hub delegated administrator can invoke this operation from the home Region. A configuration can refer to a configuration policy or to a self-managed configuration. '
      operationId: amazonWebServicesBatchGetConfigurationPolicyAssociations
      tags:
      - configurationPolicyAssociation
  /configurationPolicyAssociation/get:
    POST:
      summary: Amazon Web Services Getconfigurationpolicyassociation
      description: ' Returns the association between a configuration and a target account, organizational unit, or the root. The configuration can be a configuration policy or self-managed behavior. Only the Security Hub delegated administrator can invoke this operation from the home Region. '
      operationId: amazonWebServicesGetConfigurationPolicyAssociation
      tags:
      - configurationPolicyAssociation
  /configurationPolicyAssociation/list:
    POST:
      summary: Amazon Web Services Listconfigurationpolicyassociations
      description: ' Provides information about the associations for your configuration policies and self-managed behavior. Only the Security Hub delegated administrator can invoke this operation from the home Region. '
      operationId: amazonWebServicesListConfigurationPolicyAssociations
      tags:
      - configurationPolicyAssociation
  /configurationPolicyAssociation/associate:
    POST:
      summary: Amazon Web Services Startconfigurationpolicyassociation
      description: ' Associates a target account, organizational unit, or the root with a specified configuration. The target can be associated with a configuration policy or self-managed behavior. Only the Security Hub delegated administrator can invoke this operation from the home Region. '
      operationId: amazonWebServicesStartConfigurationPolicyAssociation
      tags:
      - configurationPolicyAssociation
  /configurationPolicyAssociation/disassociate:
    POST:
      summary: Amazon Web Services Startconfigurationpolicydisassociation
      description: ' Disassociates a target account, organizational unit, or the root from a specified configuration. When you disassociate a configuration from its target, the target inherits the configuration of the closest parent. If there’s no configuration to inherit, the target retains its settings but becomes a self-managed account. A target can be disassociated from a configuration policy or self-managed behavior. Only the Security Hub delegated administrator can invoke this operation from the home Region. '
      operationId: amazonWebServicesStartConfigurationPolicyDisassociation
      tags:
      - configurationPolicyAssociation