Start a conversation

Quicksight Remove Idle Users

Opportunity Name:

Quicksight Remove Idle Users

 

AWS Resource Type:

Quicksight users

 

Opportunity Description:

Each Quicksight user can be a reader, an author, or an admin (with Author Pro, Admin Pro, and Reader Pro variants).  Idle base (free) readers are not affected.  Idle authors, admins, Author Pro, Admin Pro, and Reader Pro users incur a per-user charge each month.  If a user is idle, they likely don’t need access to Quicksight anymore.  The user can be removed.

 

Criteria for identifying the opportunity:

The opportunity is identified if:

  • A user in that account has an Author, Admin, Author Pro, Admin Pro, or Reader Pro role (base/free Reader users are excluded)
  • The user hasn’t interacted with Quicksight (in any region) during the idle threshold period (30 days by default; configurable between 15 and 90 days, see below)

 

Configuring the Idle Threshold

By default, a user is considered idle after 30 days of inactivity. This threshold is configurable between 15 and 90 days in the same settings panel used for the exclusion pattern below (Settings tab, cog wheel beside the QuickSight finder).

Excluding Users

CloudFix’s user exclusion setting lets you prevent specific QuickSight users from being deleted by the “Delete Idle Users” Finder. It uses regular expression patterns to match usernames you want to protect, without blocking cleanup for truly idle accounts.

This is useful for keeping key accounts untouched—like service accounts, exec users, or project-related roles—even if they appear inactive.

The feature can be accessed under the Settings tab, and clicking the cog wheel beside the QuickSight finder. 

How It Works

The setting matches usernames against a regex pattern. If there's a match, the user is excluded from deletion. You can use it to protect:

  • Service accounts (e.g. .*-service-account$)

  • Admin users (admin.*|.*-admin$)

  • Executives (exec-.*|c-level-.*)

  • Project-specific accounts (project-.*-team)

  • Specific domains (.*@company\.com$)

Potential savings (range in % on annual basis):

100% of the per-seat cost for each idle user.

 

What happens when the Fixer is executed?

The user’s resources are shared with the most recently active QuickSight user in the same account (among eligible Author/Admin-tier users), preserving access to those resources.  The user is then deleted.

 

Is it possible to rollback once CloudFix implements the fixer?

CloudFix cannot roll back this fixer.  If the same user wants to access Quicksight again, they should sign up through the process they originally used to gain access.  They should consider doing so as a reader rather than an author or admin.

 

Can CloudFix implement the fix automatically once I accept the recommendation?

Yes

 

Does this fix require downtime?

No

 

Additional Resources:

Choose files or drag and drop files
Was this article helpful?
Yes
No
  1. Priyanka Bhotika

  2. Posted
  3. Updated

Comments