ExposedToAccount
Reachable/usable account/subscription/project-wide.
*
── ExposedToAccount ──▸
Account, Subscription, Project
Source types
*Target types
States
ACTIVE
CONDITIONAL
POTENTIAL
BLOCKED
UNKNOWN
Derivation
| nature | derived |
|---|
Rules that emit ExposedToAccount 5
An EFS file system with no explicit file system policy (PolicyNotFound) is fully accessible to any same-account IAM principal that can network-reach the mount target.
awsderived
A PrivateLink producer endpoint with an explicit permission granting access to a foreign account principal is exposed to cross-account consumption. This is a structural fact representing the intended cross-account data-plane exposure.
awsderived
A VPC Lattice service network or service with authType NONE is accessible to any client in any associated VPC without IAM authentication - account-scoped exposure (or broader if the network is RAM-shared).
awsderived
Batch account data-plane endpoint reachable by any key/token holder unless restricted to private endpoints.
azurederived
An API connection referencing a resource in a different subscription (same tenant) represents cross-subscription exposure.
azurederived