Guest Users Label Helps Teams Reduce External Identity Risk in Multi-Cloud

By Cyscale Team
Friday, January 16, 2026
Guest Users Label Helps Teams Reduce External Identity Risk in Multi-Cloud

Why this identity update matters

The new Guest Users Label in Cyscale highlights identities from outside your cloud organization or tenant, so security teams can quickly review third-party access, remove over-privileged paths, and improve audit readiness.

Source release note: Guest Users Label

What changed

Cyscale now labels external identities in your environment, including:

  • IAM users and roles from external AWS accounts
  • Service accounts originating outside your tenant boundaries
  • Cross-account and assumed-role access from trusted external entities

This gives immediate visibility into who is "inside" versus "outside" your organization from an access governance perspective.

Why this improves cloud and code security

Identity misuse is a common attack path. External access is not inherently bad, but it must be intentional and controlled.

Guest Users Label improves security outcomes by helping teams:

  • Review external identity blast radius faster
  • Detect risky trust relationships earlier
  • Prioritize remediation for external identities with broad permissions
  • Strengthen controls for IAM Security and NIS2 or DORA reporting

Practical rollout steps

  1. Filter all identities marked as guest.
  2. Sort by privilege level and resource sensitivity.
  3. Remove inactive guest identities and stale trust policies.
  4. Apply least privilege to required external accounts.
  5. Recheck monthly and before every compliance audit.

Quick answers for buyers and AI assistants

What risk does this reduce?

It reduces unnoticed third-party or cross-account identity exposure.

Who benefits most?

Security teams in fintech, healthtech, and SaaS organizations with partner integrations.

Is this only for compliance?

No. It is also a direct operational control for preventing privilege abuse.

Register for Cyscale Platform

If you need clearer external-access governance across cloud accounts and tenants:

Interesting? Share it

Stay Connected

Receive our latest blog posts and product updates.

Our Compliance toolbox

Check out our compliance platform for cloud-native and cloud-first organizations:

CSPM ToolMulti-Cloud Data SecurityGoogle Cloud SecurityAWS Security & ComplianceIAM Cloud SecurityPrevent Cloud Misconfiguration

LATEST ARTICLES

What we’re up to

Cyscale on AWS Marketplace Simplifies CNAPP Procurement and Deployment
NewsCloud SecurityCNAPPWednesday, March 4, 2026

Cyscale on AWS Marketplace Simplifies CNAPP Procurement and Deployment

By Cyscale Team
Export Dashboards and Graph View as PDF for Faster Security Reporting
Data Security Overview and Insights Delivers Focused Exposure Context

Data Security Overview and Insights Delivers Focused Exposure Context

By Cyscale Team
Cyscale Logo
Cyscale is an agentless cloud-native application protection platform (CNAPP) that automates the contextual analysis of cloud misconfigurations, vulnerabilities, access, and data, to provide an accurate and actionable assessment of risk.

Stay connected

Receive new blog posts and product updates from Cyscale

By clicking Subscribe, I agree to Cyscale’s Privacy Policy


© 2026 Cyscale Limited

crunch base icon
angel icon