

# Manage an IAM Access Analyzer external access analyzer
<a name="access-analyzer-manage-external"></a>

To enable an external access analyzer in a Region, you must create an analyzer in that Region. You must create an external access analyzer in each Region in which you want to monitor access to your resources.

**Note**  
After you create or update an analyzer, it can take time for findings to be available.

## Update an external access analyzer
<a name="access-analyzer-manage-external-update"></a>

Use the following procedure to update an external access analyzer.

1. Open the IAM console at [https://console.aws.amazon.com/iam/](https://console.aws.amazon.com/iam/).

1. Under **Access analyzer**, choose **Analyzer settings**.

1. In the **Analyzers** section, choose the name of the external access analyzer to manage.

1. On the **Archive rules** tab, you can create, edit, or delete archive rules for the analyzer. For more information, see [Archive rules](access-analyzer-archive-rules.md).

1. On the **Tags** tab, you can manage and create tags for the analyzer. For more information, see [Tags for AWS Identity and Access Management resources](id_tags.md).

## Delete an external access analyzer
<a name="access-analyzer-manage-external-delete"></a>

Use the following procedure to delete an external access analyzer. When you delete an analyzer, the resources are no longer monitored and no new findings are generated. All findings that were generated by the analyzer are deleted.

1. Open the IAM console at [https://console.aws.amazon.com/iam/](https://console.aws.amazon.com/iam/).

1. Under **Access analyzer**, choose **Analyzer settings**.

1. In the **Analyzers** section, choose the name of the external access analyzer to delete.

1. Choose **Delete analyzer**.

1. Enter **delete** and choose **Delete** to confirm deleting the analyzer.