Info icon
End of Life Notice: For Trend Cloud One™ - Conformity Customers, Conformity will reach its End of Sale on “July 31st, 2025” and End of Life “July 31st, 2026”. The same capabilities and much more is available in TrendAI Vision One™ Cloud Risk Management. For details, please refer to Upgrade to TrendAI Vision One™
Use the Knowledge Base AI to help improve your Cloud Posture

Detect IAM User Sign-In Requests Outside Regular Business Hours

TrendAI Vision One™ provides continuous assurance that gives peace of mind for your cloud infrastructure, delivering over 1400 automated best practice checks.

Risk Level: Low (generally tolerable level of risk)

Monitoring IAM user activity outside regular business hours can help meet security and compliance requirements and enable you to respond fast to any unauthorized user access sessions or security breaches. TrendAI Vision One™ Cloud Risk Management Real-Time Threat Monitoring and Analysis (RTMA) engine can detect in real time any AWS Management Console sign-in requests initiated by IAM users. An IAM user is an identity created for your Amazon Web Services account that has specific custom permissions (for example, permissions to manage KMS Customer Master Keys). You can use an IAM user name and password to sign in to AWS Management Console in order to access all AWS cloud resources - when the user has admin-level privileges, or a certain service or resource - when the user has a specific set of permissions that follows the principle of least privilege. TrendAI Vision One™ Cloud Risk Management RTMA integrates seamlessly with Amazon CloudTrail service which logs all sign-in attempts (successes and failures) made by IAM users. The RTMA engine scans the log files generated by AWS CloudTrail for logging data associated with IAM user sign-in requests, logging data that includes the time when the request was made, the IP address of the user signing in, the user agent used and whether MFA was enforced for that sign-in or not, then sends notifications to the recipients configured in the TrendAI Vision One™ Cloud Risk Management Dashboard settings whenever an IAM sign-in request is made outside regular business hours. The communication channels necessary for sending RTMA notifications can be easily configured within your TrendAI Vision One™ Cloud Risk Management Dashboard. The list of supported communication channels that you can use to receive alerts for AWS IAM sign-in requests outside 9AM – 5PM time interval, are SMS, Email, Slack, PagerDuty, ServiceNow and Zendesk.

Security

Monitoring IAM access in real-time is essential for keeping your Amazon Web Services account secure as it helps you gain more visibility into your account user activity. The AWS IAM user sign-in requests made to AWS Management Console outside regular business hours are automatically labeled as suspicious. Allowing IAM users to access your AWS account outside regular business hours (i.e. outside 9AM – 5PM interval) could be very problematic because these authentication requests are usually performed by unauthorized people. Once this RTMA rule is enabled, the system sends notifications whenever AWS Management Console sign-in requests are performed outside the 9AM – 5PM timeframe. Besides granting your IAM users the minimum amount of privileges necessary to perform their assigned tasks, TrendAI Vision One™ Cloud Risk Management strongly recommends using this rule to monitor your IAM user activity outside regular business hours.


References

Publication date Sep 9, 2018