React to specific IAM Events in AWS
15:09 05 Dec 2025

What I am trying to achieve is to trigger specific actions within my AWS Account when specific IAM actions are performed. This appeared to be much more complicated than I expected, so I wanted to provide my solution here, as I wonder if that's the way to go:

  • For the AWS Service that I use to "react" to specific IAM events, I came to the conclusion that the best solution for this is the Amazon EventBridge service.
  • As my AWS Account does not sit within the us-east-1 region, this cannot be directly done, as IAM events are exclusively sent to the us-east-1 region in AWS (see this and this).
  • According to this guide, I thus had to create two event buses in Amazon EventBridge; one in the us-east-1 region (A) and one in the region of my AWS account (B), as follows:

A) As IAM events are exclusively sent to Amazon EventBridge over CloudTrail:

This first event bus setup in us-east-1 uses the following input event pattern if I want to e.g. react to the CreateUser IAM Event:

{
  "source": ["aws.iam"],
  "detail-type": ["AWS API Call via CloudTrail"],
  "detail": {
    "eventSource": ["iam.amazonaws.com"],
    "eventName": ["CreateUser"]
  }
}

...while the eventName may be any action name listed here. As a target, I specify the ARN of the event bus B), which I detailed below.

B) This event bus is setup in the region of my own AWS account, and uses the exact same input event pattern as A), as event bridge events forwarded among event buses remain unchanged. For the target, I then specify whatever I want to do with my event, e.g. execute a lambda function based on the input event, etc.

So far so good, but this still does not work. Although I can see the CreateUser event showing up in my CloudTrail event history, EventBridge does not react to it, it does not even register the occurrence of the event.

It seems that I actually have to setup a CloudTrail Trail for the concerned IAM events log, even if I can already see the concerned cloud trail events in my event history. EventBridge only reacts to cloud trail events if they come from a cloud trail, and not simply if they're logged. Is this true?

Then, to make things even more complicated, for my setup, I only need a Cloud Trail Trail for the us-east-1 region, as I simply have to make sure that my IAM Events flow into my event bridge bus in that same us-east-1 region (event bus A). According to the docs, you can however only setup single-region trails via the CLI. To make things even more complicated, creating a cloud trail trail requires an S3 bucket, according to the docs. You will also be prompted to create an AWS KMS encryption key to encrypt the generated trail files at rest.

So in the end, all I wanted to do is run an AWS Lambda function when the CreateUser IAM service event happens in my AWS account, using EventBridge. This is possible at basically no cost - that's what I thought. As the actual minimally needed setup looks like this now:

  • Create an additional single-regional cloud trail trail in us-east-1.
  • Create an additional S3 Bucket in that same region, as I cannot create a trail without that.
  • Create an AWS KMS key for encryption of the trail at rest (this cannot be disabled??)
  • Create an event bridge event bus in the region us-east-1, which forwards the concerned events from the event bus (A) to the event bus (B) I have to additionally setup in my region.

All of this seems terribly complicated and introduces a variety of costs that have basically absolutely no use at all for my integration. Can't you connect IAM events in an easier way with AWS Lambda Executions?

amazon-web-services aws-lambda amazon-iam aws-event-bridge amazon-cloudtrail