IAM Access Analyzer reports unused administrative roles in a parks department account that still trust a broad set of principals. What should the security architects do to improve least privilege?
Select an answer to reveal the explanation.
Short Explanation
Unused admin roles are spare master keys left in the parks shed—harmless until someone finds them. Access Analyzer is the inventory clipboard; delete or shrink what nobody needs. Least privilege is a continuous cleanup, not a one-time workshop slide.
Full Explanation
Auditing for least privilege includes acting on IAM Access Analyzer findings about unused or overly permissive roles. Continuous improvement means removing dormant administrative identities and narrowing trust policies and permissions to documented operational need. Ignoring unused roles, broadening instance-profile admin rights, or sharing unused admin roles org-wide increases attack surface. Professional remediation pairs discovery tooling with deliberate privilege reduction in the municipal account.