AWS IAM

Ceven provisions IAM users with the right policies on hire, automates access key rotation while they are working, and on offboarding disables console login, deactivates every key, and detaches MFA so nothing lingers.

What Ceven does with AWS IAM

  • IAM user provisioning with scoped policies
  • Periodic access key rotation
  • Console password disable on exit
  • Access key deactivation
  • MFA device detachment
  • Audit-grade event log export

Connecting AWS IAM

Ceven connects to AWS IAM with read-scoped API credentials, added under Settings, then Integrations in your Ceven dashboard. You provide:

  • AWS access key ID
  • AWS secret access key. From IAM → Users → your user → Security credentials.
  • AWS region
Where to find these in AWS IAM

Frequently asked questions

What do I need to connect AWS IAM to Ceven?
Connecting AWS IAM takes 3 fields: AWS access key ID, AWS secret access key, AWS region. You enter them under Settings, then Integrations in your Ceven dashboard.
What can Ceven's agents do with AWS IAM?
With AWS IAM connected, Ceven handles IAM user provisioning with scoped policies, Periodic access key rotation, Console password disable on exit, and more.

More Engineering integrations

Setting up AWS IAM? Email support@ceven.io with your tenant ID, or security@ceven.io for security questions.