To generate a report
In addition to using credential reports, you can also determine when a password or access key was last used by using these IAM APIs:
ListUsers (AWS CLI command: aws iam list-users)
GetUser (AWS CLI command: aws iam get-user)
GetAccessKeyLastUsed (AWS CLI command: aws iam get-access-key-last-used)
-
http://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_getting-report.htmlPremières choses à faire, best practice concernant iam. En résumé : ne pas générer d'access key pour l'utilisateur "root", créer des users avec des droits bien determinés.
-
http://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html