> For the complete documentation index, see [llms.txt](https://docs.forestall.io/forestall/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.forestall.io/forestall/unified-identities/aws-identities/groups.md).

# Groups

The Groups page provides a list of enumerated IAM groups in the entire AWS environment. The list contains the Member Count, Tier 0, Shadow, Risk Score, Exposure Point and Issue Counts.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-e33c7d352be8807b5e4694c28ec445d6ba0a1a1f%2Faws-group-list-view.png?alt=media" alt=""><figcaption><p>Groups</p></figcaption></figure>

## Group Details

Details page contains the Risk Score of the group, Exposure Point, Information and Issues panes.

You can analyze objects in the Graph module by clicking the Visualize button on the upper left side of the Information Pane.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-24e9499730f2f1befd82a42225c88962015a9d1c%2Faws-identities-groups-image-1.png?alt=media" alt=""><figcaption><p>Group Details</p></figcaption></figure>

## Information

Information Pane can contain different badges to highlight important attributes.

| Badge        | Description                                                                           |
| ------------ | ------------------------------------------------------------------------------------- |
| Tier         | Indicates that the object tier according to risk score and importance.                |
| Shadow Admin | Indicates that the object can compromise admin objects with at least one attack path. |

Information Pane contains Details, Users and Policies tabs.

## Details

Details tab contains attributes below about the IAM group object.

| Attribute    | Description                                                                 |
| ------------ | --------------------------------------------------------------------------- |
| Group Name   | The name of the IAM group, used for identification within AWS.              |
| Group ID     | The unique identifier assigned to the IAM group by AWS.                     |
| ARN          | The Amazon Resource Name that uniquely identifies the IAM group across AWS. |
| Account ID   | The AWS account ID that the IAM group belongs to.                           |
| Path         | The path associated with the IAM group, used for organizational grouping.   |
| Member Count | The number of IAM users that are members of this group.                     |
| Created      | The date and time when the IAM group was created.                           |
| Object ID    | The unique identifier of the group object, equivalent to the IAM Group ID.  |

## Users

Users tab contains a list of IAM users that are members of the group.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-229f789e8a3515d2f98f03c71e9e15d8b259230c%2Faws-identities-groups-image-2.png?alt=media" alt=""><figcaption><p>Users</p></figcaption></figure>

## Policies

Policies tab contains a list of IAM policies attached to the group, including both managed and inline policies. This list also contains columns such as AWS Managed and Grants Admin Privileges to identify the scope and risk level of each policy.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-4cf6013c02ca516622b54ea026fc881592239835%2Faws-identities-groups-image-3.png?alt=media" alt=""><figcaption><p>Policies</p></figcaption></figure>

## Issues

Issues pane contains identified security issues on the IAM group object.
