US 12,238,106 B1
Troubleshooting policy-based permissions
Homer Strong, Seattle, WA (US); and Lucie Klimosova, Seattle, WA (US)
Assigned to Amazon Technologies, Inc., Seattle, WA (US)
Filed by Amazon Technologies, Inc., Seattle, WA (US)
Filed on Dec. 10, 2021, as Appl. No. 17/547,659.
Int. Cl. H04L 29/06 (2006.01); H04L 9/40 (2022.01)
CPC H04L 63/101 (2013.01) [H04L 63/0263 (2013.01); H04L 63/20 (2013.01)] 16 Claims
OG exemplary drawing
 
1. A computing system comprising:
one or more hardware processors; and
one or more memories having stored therein instructions that, upon execution by the one or more hardware processors, cause the computing system to perform computing operations comprising:
receiving, by an identity management service, one or more indications of a decision to deny an attempted access of a computing resource by an identity, wherein an evaluation of the decision to deny the attempted access is performed based at least in part on a log analysis that indicates more than a threshold quantity of access denial errors within a given time period;
providing, for display, an interface of an activity monitoring service that shows a relationship between policy changes made by a user and the access denial errors, the interface identifying a first time at which the policy changes are made by the user and a second time at which an increase occurred in an amount of the access denial errors;
determining, by the identity management service, a plurality of relevant access permission policies whose permissions are evaluated as inputs to the decision to deny the attempted access;
determining, by the identity management service, one or more explicit deny policies of the relevant access permission policies that explicitly deny the attempted access;
determining, by the identity management service, one or more implicit deny policies of the relevant access permission policies that implicitly deny the attempted access;
providing, by the identity management service, at least one explicit deny indication of at least one of the one or more explicit deny policies; and
providing, by the identity management service, at least one implicit deny indication of at least one of the one or more implicit deny policies.