frontdoor rule · FD021

Unused AWS OIDC or SAML identity provider

Stale federation

Amazon Web Services, Google CloudUpdated Source on GitHub

Severity: medium.

What it means

Two shapes of the same problem: access that exists but nobody uses.

An identity provider nothing references. A registered OIDC or SAML provider, or a GCP workload identity pool, with no role or service account bound to it. It is a door frame with no door — still standing, still usable.

A role or binding nobody has walked through. An external trust that has never been assumed, or not assumed in --stale-days (default 90).

Why it matters

The provider case is the sharper one. Anyone who can write an IAM trust policy can point a role at an already-registered provider without creating anything that looks new. Reviewers see a provider that has been there for two years and assume it is in use. Registering a new provider is a conspicuous act; attaching to an old one is not.

The unused-role case is quieter: unused access is the access that gets forgotten, and forgotten access is what incident write-ups are made of. There is no usage pattern for an anomaly detector to notice a deviation from.

How to fix it

AWS

bash
aws iam delete-open-id-connect-provider --open-id-connect-provider-arn ARN
aws iam delete-saml-provider --saml-provider-arn ARN

Check every account in the organization first — frontdoor only sees the one it was pointed at.

GCP

bash
gcloud iam workload-identity-pools providers delete PROVIDER --workload-identity-pool=POOL --location=global
gcloud iam workload-identity-pools delete POOL --location=global

A deleted pool is recoverable for 30 days, which makes this a safe thing to try.

For a stale role, check CloudTrail across all regions before deleting. If the role is still wanted but the external trust is not, delete just that statement.

What this finding will not claim

AWS only began recording role last-used data in 2019, and it is region-scoped. When the creation date is unknown, frontdoor says nothing at all rather than calling a role stale on no evidence — "never used" with no idea how long is not evidence of anything. A role created last week is new, not stale.

frontdoor answers this once, when you run it; Secorvia checks it continuously across every account you connect, on a free tier that needs no card.