CIEM per-cloud notes
What CIEM does on each cloud today. AWS has the deepest coverage; the other clouds are honest subsets, and this page is where we say which.
AWS
- Identities: IAM users, roles, groups, instance profiles, managed and inline policies, trust policies.
- Effective access: full chain — group expansion, condition classes, explicit-deny netting, SCP deny checks. See effective permissions for what is not modelled yet.
- Escalation: PassRole, multi-hop assume-role chains, boundary bypass, service-linked role creation; shadow admins (four patterns); CDR confirmation.
- Trust: foreign accounts, wildcard principals, missing ExternalId, SAML and OIDC federation — including GitHub, GitLab, GCP and Azure issuers.
- Non-human identities: roles classified as service-linked, AWS service, execution (Lambda, ECS and similar), CI/CD over OIDC, EKS service account (IRSA), cross-account, user-assumable or wildcard.
- Usage: CloudTrail-based permission gap and stale roles.
- Scoring and reviews: risk score, blast radius and access reviews.
- Needs: CloudTrail flowing into Onam's threat detection for the usage-based findings; read access to AWS Organizations for SCP checks.
Azure
- Identities: role definitions and assignments, Entra service principals, managed identities (user- and system-assigned).
- Effective access: assignments joined to role definitions, scope classified, ABAC conditions evaluated. Entra group membership is not expanded.
- Escalation: RBAC Owner, PIM activation, service principal owner rights.
- Trust and scope: cross-tenant access without conditional access; service principals and managed identities with Owner, Contributor or User Access Administrator at broad scope; guests with privileged roles.
- Graph: VM → managed identity links.
Google Cloud
- Identities: IAM bindings, service accounts, workload identity pools.
- Effective access: bindings on projects, service accounts, buckets, BigQuery datasets and Pub/Sub topics, mapped onto the shared access levels.
- Escalation: service-account key creation, primitive (owner/editor) roles, broad workload identity.
- Findings: service accounts with Owner, keys past rotation age, public principals in bindings, workload identity pools without an attribute condition, service-account chaining.
- Graph: compute instance → service account links.
Kubernetes
- Identities: service accounts, Roles and ClusterRoles, RoleBindings and ClusterRoleBindings, pods.
- Effective access: bindings resolved to service accounts and their rules.
- Escalation: cluster-admin bindings, Role and ClusterRole write, pods/exec and pods/attach, cluster-wide secrets read, node access, cross-namespace escalation.
- Graph: pod → service account links; workload-identity annotations to the cloud identity.
OCI
- Identities: users, groups, policies, dynamic groups, API keys, auth tokens, customer secret keys.
- Escalation: policy, group or user management; tenancy admin; secret access; broad dynamic-group matching rules; instance principals.
- Hygiene: MFA, key and token rotation, Administrators group membership, inactive users with credentials.
Alibaba Cloud
- Identities: RAM users, roles, groups, policies, access keys.
- Findings: wildcard or admin policies, RAM roles with wildcard trust or assumable without MFA, broad OSS and KMS grants, access-key rotation, console MFA.
IBM Cloud
- Identities: API keys, service IDs, trusted profiles, access groups, policies.
- Escalation: IAM identity admin, access-group management, API-key creation for service IDs, secrets access.
- Trust: trusted profiles that trust another account.
- Hygiene: account MFA enforcement, API-key rotation.
Not yet on these clouds
Unused-permission analysis, shadow-admin detection, the risk score and automatic access reviews run on AWS identities today. Multi-hop assume-role chains are AWS-only.