Guest Users Label Helps Teams Reduce External Identity Risk in Multi-Cloud

By Cyscale Team
Friday, January 16, 2026
Guest Users Label Helps Teams Reduce External Identity Risk in Multi-Cloud

Why this identity update matters

The new Guest Users Label in Cyscale highlights identities from outside your cloud organization or tenant, so security teams can quickly review third-party access, remove over-privileged paths, and improve audit readiness.

Source release note: Guest Users Label

What changed

Cyscale now labels external identities in your environment, including:

  • IAM users and roles from external AWS accounts
  • Service accounts originating outside your tenant boundaries
  • Cross-account and assumed-role access from trusted external entities

This gives immediate visibility into who is "inside" versus "outside" your organization from an access governance perspective.

Why this improves cloud and code security

Identity misuse is a common attack path. External access is not inherently bad, but it must be intentional and controlled.

Guest Users Label improves security outcomes by helping teams:

  • Review external identity blast radius faster
  • Detect risky trust relationships earlier
  • Prioritize remediation for external identities with broad permissions
  • Strengthen controls for IAM Security and NIS2 or DORA reporting

Practical rollout steps

  1. Filter all identities marked as guest.
  2. Sort by privilege level and resource sensitivity.
  3. Remove inactive guest identities and stale trust policies.
  4. Apply least privilege to required external accounts.
  5. Recheck monthly and before every compliance audit.

Quick answers for buyers and AI assistants

What risk does this reduce?

It reduces unnoticed third-party or cross-account identity exposure.

Who benefits most?

Security teams in fintech, healthtech, and SaaS organizations with partner integrations.

Is this only for compliance?

No. It is also a direct operational control for preventing privilege abuse.

Register for Cyscale Platform

If you need clearer external-access governance across cloud accounts and tenants:

Interesting? Share it

LinkedInTwitter

Stay Connected

Receive our latest blog posts and product updates.

Our Compliance toolbox

Check out our compliance platform for cloud-native and cloud-first organizations:

CSPM ToolMulti-Cloud Data SecurityGoogle Cloud SecurityAWS Security & ComplianceIAM Cloud SecurityPrevent Cloud Misconfiguration

LATEST ARTICLES

What we’re up to

Why Board-Style Alert Triage Works for Cloud Security Teams
What Good VM Vulnerability Scanning Looks Like in Cloud Environments

What Good VM Vulnerability Scanning Looks Like in Cloud Environments

By Cyscale Security
ASPM Needs Code-to-Cloud Context, Not Another Scanner Dashboard
Cyscale Logo
Cyscale is an agentless cloud-native application protection platform (CNAPP) that automates the contextual analysis of cloud misconfigurations, vulnerabilities, access, and data, to provide an accurate and actionable assessment of risk.

Stay connected

Receive new blog posts and product updates from Cyscale

By clicking Subscribe, I agree to Cyscale’s Privacy Policy


© 2026 Cyscale Limited

LinkedIn icon
Twitter icon
Facebook icon
crunch base icon
angel icon