frontdoor rule · FD021
Unused AWS OIDC or SAML identity provider
Stale federation
Severity: medium.
What it means
Two shapes of the same problem: access that exists but nobody uses.
An identity provider nothing references. A registered OIDC or SAML provider, or a GCP workload identity pool, with no role or service account bound to it. It is a door frame with no door — still standing, still usable.
A role or binding nobody has walked through. An external trust that has
never been assumed, or not assumed in --stale-days (default 90).
Why it matters
The provider case is the sharper one. Anyone who can write an IAM trust policy can point a role at an already-registered provider without creating anything that looks new. Reviewers see a provider that has been there for two years and assume it is in use. Registering a new provider is a conspicuous act; attaching to an old one is not.
The unused-role case is quieter: unused access is the access that gets forgotten, and forgotten access is what incident write-ups are made of. There is no usage pattern for an anomaly detector to notice a deviation from.
How to fix it
AWS
aws iam delete-open-id-connect-provider --open-id-connect-provider-arn ARN
aws iam delete-saml-provider --saml-provider-arn ARNCheck every account in the organization first — frontdoor only sees the one
it was pointed at.
GCP
gcloud iam workload-identity-pools providers delete PROVIDER --workload-identity-pool=POOL --location=global
gcloud iam workload-identity-pools delete POOL --location=globalA deleted pool is recoverable for 30 days, which makes this a safe thing to try.
For a stale role, check CloudTrail across all regions before deleting. If the role is still wanted but the external trust is not, delete just that statement.
What this finding will not claim
AWS only began recording role last-used data in 2019, and it is region-scoped.
When the creation date is unknown, frontdoor says nothing at all rather than
calling a role stale on no evidence — "never used" with no idea how long is not
evidence of anything. A role created last week is new, not stale.
frontdoor answers this once, when you run it; Secorvia checks it continuously across every account you connect, on a free tier that needs no card.