The firewall moved. Your IAM policies are now the outer wall — and most teams still treat them like internal plumbing.
The checklist
- Enforce MFA on every human and service principal
- Maximum session duration: 1 hour for privileged roles
- No inline policies — use managed policies with version control
- Quarterly access reviews with automated stale-role detection
- Break-glass accounts: two, monitored, never used in normal operations
AN3 Intel Brief · Cloud defense across AWS, Azure, and GCP.