What Is AWS Trusted Advisor? The 56 Free Checks Explained

Logeshwaran
—

AWS Trusted Advisor is the built-in AWS service that scans your account for best-practice problems and turns them into recommendations. On Basic Support, you do not get the full catalog, but you still get every Service Limits check plus selected Security and Fault Tolerance checks. The counterintuitive part is that the old “only four free checks” advice is no longer a safe description of the current product: AWS now counts 56 checks that every account can use, with no premium support plan required.

⚡ Quick Answer

• Console → AWS Management Console → Trusted Advisor → Recommendations.

• Basic Support → all Service Limits checks plus selected Security and Fault Tolerance checks.

• Full access → Business Support+, Enterprise Support, and Unified Operations unlock the full check set and Trusted Advisor API.

If you only read one section, use the 10-minute first pass and clear the red findings you understand before buying anything.

Trusted Advisor is not a person watching your account and it is not an automatic repair tool. Think of it as a dashboard of inspections. Each check looks for a defined condition, such as a service quota approaching its limit, an S3 bucket permission that deserves attention, a root account without MFA, an unrestricted security-group rule, or a resource pattern that may be wasting money. It then shows the result and a recommended next action.

Jake runs a small phone shop. His AWS account is not impressive: one booking page, a few S3 buckets, a database, and several test resources that somehow survived longer than the ideas that created them. He assumed Trusted Advisor was “one of those enterprise things” and ignored the menu item for months. Ethan’s answer is simple: “If AWS is already willing to point at the smoke for free, at least look before you buy a bigger fire extinguisher.”

What is AWS Trusted Advisor?

Trusted Advisor evaluates your AWS environment against a library of best-practice checks. Its purpose is to turn a large account into a shorter list of things worth looking at. Instead of making you remember every quota, exposure pattern, resilience setting, and cost clue across dozens of services, it brings recommendations into one place.

The useful mental model is inspection, not enforcement. A red result means action is recommended. Yellow means investigation is recommended. Green means the check did not detect a problem. Gray represents excluded items. None of those colors is permission to change production without understanding the resource first.

That distinction matters because a recommendation can be technically valid and still need business context. A deliberately public S3 bucket used for a public artifact is not the same decision as a bucket containing customer invoices. A lightly used EC2 instance that exists as a deliberate standby is not the same thing as a forgotten development server. Trusted Advisor sees conditions. You still own the reason the resource exists.

The current check categories are Cost Optimization, Performance, Security, Fault Tolerance, Service Limits, and Operational Excellence. Some recommendations are native Trusted Advisor checks. Others can surface from services such as AWS Compute Optimizer, AWS Security Hub CSPM, AWS Config-backed checks, or the Well-Architected Tool when the relevant integrations are in use.

CategoryQuestion it helps answerTypical next move
Cost OptimizationAm I paying for something that looks unnecessary or oversized?Validate usage, then resize, stop, delete, or leave it intentionally.
PerformanceIs a configuration likely to constrain performance?Review workload requirements and the affected resource.
SecurityIs a setting increasing exposure or weakening account protection?Treat red findings as urgent review items.
Fault ToleranceWould a failure leave this workload with too little redundancy?Compare the recommendation with the workload's availability target.
Service LimitsAm I getting close to a service quota?Free unused capacity or request a quota increase when available.
Operational ExcellenceAre operating practices drifting from recommended patterns?Review the recommendation in the context of your operating model.

Which Trusted Advisor checks are free?

With Basic Support, the Trusted Advisor console gives you all checks in the Service Limits category and a selected group from Security and Fault Tolerance. The named checks currently include Amazon EBS Public Snapshots, Amazon RDS Public Snapshots, Amazon S3 Bucket Permissions, MFA on root account, Security Groups – Specific Ports Unrestricted, and AWS STS global endpoint usage across AWS Regions.

That is the clean answer to “is AWS Trusted Advisor free?” The service has a useful free core, but the complete recommendation catalog is tied to higher support plans. Basic Support comes with an AWS account, so you can open Trusted Advisor and use that core without adding a premium support subscription.

Old tutorials often say “four free checks.” That number came from an older version of the product. It is not the current Basic-plan description. If you are auditing an account in 2026, trust the current console and current check reference rather than trying to make your screen match an old screenshot.

‍♂️ Jake's Reality Check

"So if I am on the free support plan, there is still something worth opening?"

Yes. Start with Service Limits and the available security checks. You do not need to upgrade just to discover whether your root account lacks MFA or whether a supported quota check is warning you.

There is one operational limitation on Basic Support: automatic check updates are not available in the same way as the higher support tiers. Security checks on Basic can require a manual refresh. If you changed a permission and still see the old result, refresh the relevant check before deciding the change failed.

Business Support+, Enterprise Support, and Unified Operations provide access to the full Trusted Advisor check set. They also unlock programmatic access through the Trusted Advisor API. AWS’s Trusted Advisor page puts the full catalog at 482 checks: the 56 that every account can use, plus 426 more that Business Support+ and the higher plans unlock.

The API matters when you want Trusted Advisor to become part of operations instead of a dashboard someone remembers once a quarter. You can retrieve recommendations, build internal reporting, feed findings into workflow systems, and aggregate recommendations where your account and organization setup allows it. If you call the API without an eligible plan, you get an entitlement failure; adding more IAM permissions does not turn Basic into a paid plan.

Do not upgrade solely because “more checks” sounds good. Upgrade when you have a concrete reason: you need the broader recommendation set, the API, the support response features, or the organization-wide operational tooling that justifies the Support plan as a whole.

✅ Why this is the one to use

For a small account, exhaust the Basic checks first. For a production estate with many accounts, recurring reviews, and automation needs, treat the full Trusted Advisor feature set as one part of the Support-plan decision.

As of October 2026, Business Support+ has a $29 monthly minimum per account, with the actual charge being the minimum or the applicable usage-based amount, whichever is greater. That is a floor, not a promise that every account pays exactly $29.

What do red, yellow, green, and gray mean?

Red is Action recommended. Yellow is Investigation recommended. Green is No problems detected. Gray represents excluded items. Those labels look obvious until someone treats red as “AWS says delete this resource” and causes a production incident.

A red result means the check’s alert criteria were met. Your job is to inspect the affected item, read the criteria and recommended action, and decide what change is safe. Trusted Advisor does not know that Jake keeps a quiet instance because it is a manual fallback for a yearly sales event. It sees configuration and usage signals that match a rule.

Yellow deserves more respect than it gets. It often means a condition deserves investigation before it turns into an urgent problem. If you only filter to red, you use Trusted Advisor as an alarm bell and throw away its value as an early-warning system.

Green is not a security certificate. It means the particular check did not detect an issue under its current criteria. Trusted Advisor does not replace IAM design, Security Hub, logging, backups, monitoring, patching, architecture review, or threat detection.

Gray can be completely healthy when the exclusion is deliberate. The important part is being able to explain why that resource was excluded and when the exception will be reviewed again.

The 10-minute first pass I would do on every account

Do not begin by trying to understand every category. Begin with a short triage pass. The goal is not to “make Trusted Advisor green.” The goal is to find obvious risk and obvious capacity problems without changing anything you do not understand.

  1. Open Trusted Advisor → Recommendations. Note your Support plan and which categories are visible.
  2. Open Security first. Review red items before yellow items. On Basic, manually refresh supported security checks after making changes.
  3. Open Service Limits. Look for quotas that could block a deployment, migration, or growth event.
  4. Open Fault Tolerance. Decide whether flagged workloads are production, test, or intentionally single-point.
  5. If you have the full check set, open Cost Optimization. Sort recommendations by business relevance, not by how satisfying the delete button looks.
  6. Give every action an owner. “Database team to review by Friday” is better than “we will come back later.”
  7. Refresh after the change when the check supports it. Some checks update on their own schedule, so not every status changes immediately.

Jake’s version is even shorter: security exposure, quotas, then money. Ethan tells him, “You do not optimize a shop by switching off the alarm first because the battery costs money.” Cost comes after you understand what you are touching.

The free security checks are not toy checks

The Basic-plan security core is small compared with the full catalog, but the problems it catches deserve attention. Public EBS or RDS snapshots can expose data in ways you did not intend. S3 bucket permission findings can point at public access conditions or situations where Trusted Advisor cannot evaluate the policy. The root-MFA check catches a foundational account-protection issue. The security-group check looks for specific ports that are unrestricted.

Do not read a security finding like a spelling warning in an editor. Open the affected resource. Confirm the account, Region, resource ID, and business purpose. Then decide whether the exposure is intended. A resource named “test” is not automatically safe to expose, and a resource named “prod” is not automatically wrong to expose if public access is literally its job.

The Amazon S3 Bucket Permissions check is a good example of why the color is not the whole story. Current criteria can flag public-access conditions, and a red status can also appear when Trusted Advisor cannot evaluate the bucket policy. “Red” therefore means investigate now; it does not tell you the full cause until you open the recommendation.

The root-account MFA check has a modern Organizations wrinkle as well. Member-account root credentials can be centrally managed, so the right response can differ from an old checklist that assumes every member account has independently managed root credentials. Review your current organization design instead of treating a decade-old blog post as policy.

⚠️ What this actually breaks

Blindly “fixing” a public-access recommendation can take down content that is intentionally public. Confirm what the resource serves before tightening a bucket policy, security group, or snapshot-sharing configuration.

Why Service Limits is the free category to check before launches

A service quota is an AWS limit on how much of a resource or operation your account can use. Some quotas can be increased and some cannot. The worst time to discover one is during a deployment, a migration window, or a traffic spike.

Trusted Advisor’s Service Limits category gives Basic customers a way to see quota risk next to other operational recommendations. If a check shows you are approaching a limit, decide whether to release unused capacity, redesign the workload, or request a quota increase through the current quota-management route.

Do not assume every quota is global. Many limits have account and Region scope. A deployment can fail in one Region while the same resource type is nowhere near its limit somewhere else. If the warning names a Region, that Region is part of the finding, not decorative metadata.

Also do not mistake Trusted Advisor for the entire quota-management interface. AWS Service Quotas is the service built for viewing and requesting many quota increases. Trusted Advisor is valuable because it surfaces quota risk alongside security, resilience, performance, and cost recommendations.

For Jake’s shop, quota review feels boring right up until the morning a seasonal promotion needs more capacity. Boring on Tuesday is exactly what you want from something that prevents panic on Saturday.

Trusted Advisor cost optimization: useful, but never a delete list

With an eligible paid Support plan, Cost Optimization recommendations can highlight potential savings and affected resources. This is one of the reasons people discover Trusted Advisor in the first place, but cost recommendations are where blind automation is most dangerous.

A recommendation is evidence that a resource matches a cost pattern, not evidence that the resource has no business value. Before resizing, stopping, or deleting anything, answer four questions: who owns it, what depends on it, when was it last intentionally used, and how would you recover if the change were wrong?

Some recommendation sources depend on other AWS services being enabled. Compute Optimizer can contribute EBS and Lambda sizing-related checks when you opt in. Security Hub CSPM and AWS Config can enrich Trusted Advisor under their relevant integrations. That means two accounts on the same Support plan can still show different practical coverage because their services, resources, and integrations differ.

There is also a freshness trap. On January 9, 2026, five Cost Optimization Trusted Advisor checks were deprecated: Savings Plans, RDS Reserved Instance Optimization, Redshift Reserved Node Optimization, ElastiCache Reserved Node Optimization, and OpenSearch Service Reserved Instance Optimization. If an internal runbook still tells your team to hunt for those check names, the runbook is stale.

 What changed in 2026

  • January 9, 2026: five older cost optimization checks were deprecated.
  • February 19, 2026: the Idle NAT gateways cost optimization check was added.
  • August 27, 2026: the Security Hub CSPM integration reference was updated to the supported control set available through July 8, 2026.
  • September 8, 2026: a new Operational Excellence check flags EC2 instances on Nitro v4 that run an outdated ENA network driver.

Idle NAT gateways are a good example of the kind of recommendation that can save money without being a license to delete blindly. A NAT gateway can be quiet because nobody needs it, or quiet because it is part of a low-frequency path that becomes critical during deployment, recovery, or patching. The finding starts the conversation; the network owner ends it.

Worked example: should a small account pay for full Trusted Advisor?

Suppose Jake has one AWS account and is considering Business Support+ mainly because he wants the complete Trusted Advisor catalog and API access. The current minimum is $29 per month per account, although the actual fee can be higher because the plan charges the greater of the minimum or the applicable usage-based amount. That usage-based amount starts at 9% of the first $10,000 of monthly AWS charges, so the $29 floor is what an account pays until its AWS bill passes roughly $322 a month.

At the minimum, twelve months would be $29 × 12 = $348. That is not the “price of Trusted Advisor.” It is the annualized minimum of the entire Business Support+ plan if the account remained at the monthly minimum. The plan includes support capabilities beyond Trusted Advisor.

QuestionJake's caseDecision signal
Can Basic already show his immediate risks?He mainly needs root MFA, S3 permissions, open-port, snapshot, and quota review.Use Basic first.
Does he need API automation?No. One person reviews the account.No upgrade pressure from automation.
Would the full catalog change regular decisions?Maybe later as the account grows.Re-evaluate when complexity changes.
What is the annualized minimum support floor?$29 × 12$348, before any higher usage-based charge.

Ethan’s opinion is direct: “Do not spend $348 at the minimum just to avoid opening the free page you already have. Use the Basic checks. Upgrade when the broader support package solves a problem you can name.”

That is why “Trusted Advisor is free” and “Trusted Advisor is paid” are both incomplete. The core is available with Basic. The full catalog and programmatic capabilities are tied to eligible paid support plans.

Why a Trusted Advisor check can stay red after you fix it

One of the most frustrating Trusted Advisor moments is fixing a setting and seeing the old recommendation remain. Start with refresh behavior before undoing your fix.

On Basic Support, automatic updates are not generally available in the same way as on higher plans, and available Security checks can be manually refreshed. On Business Support+, Enterprise Support, and Unified Operations, Trusted Advisor automatically refreshes checks weekly, while some individual checks refresh more often on their own schedule.

Some automatically refreshed checks cannot be manually refreshed. Trying to force a refresh through an API operation can return an invalid-parameter style error for checks that own their refresh schedule. Security Hub CSPM-derived checks are another example: their results refresh at least daily, and the Trusted Advisor console does not let you manually refresh those findings.

Security Hub data also has a pipeline delay. After you enable a security standard, Security Hub CSPM can take up to two hours to produce findings, and then it can take up to 24 hours for that data to appear in Trusted Advisor. A finding that remains visible five minutes after a change does not prove the change failed.

The safe order is: verify the source configuration first, understand the check’s refresh model second, and use the Trusted Advisor status as the later confirmation. Reversing a correct security change just because a dashboard is stale is the cloud version of repainting a wall because the old photograph still shows the old color.

Should you exclude a Trusted Advisor recommendation?

Yes, when the recommendation is understood and the exception is intentional. Excluding an item tells Trusted Advisor not to keep presenting that resource in the normal result set for the check. It is not a fix and it does not modify the AWS resource itself.

That can be exactly right for a deliberate exception. Maybe a resource is kept for a documented recovery pattern. Maybe public access is required. Maybe a cost recommendation conflicts with a reliability requirement. The mistake is using Exclude as an “inbox zero” button without recording why.

When you open a specific check, Trusted Advisor lets you view affected items and include or exclude them. You can later inspect excluded items and include them again. For automation-capable customers, the newer Trusted Advisor API has recommendation resource-exclusion operations, with separate rules around Priority recommendation resources.

Security Hub CSPM resources have a special relationship with suppression. If the Security Hub workflow status for a resource is SUPPRESSED, it appears as excluded in Trusted Advisor. You do not suppress the underlying Security Hub finding from the Trusted Advisor console; you do that in Security Hub.

A healthy exception has an owner, a reason, and a review date. An unexplained exclusion is just a future mystery with a gray icon.

Trusted Advisor API and CLI: where the old examples trip you up

There are two histories sitting next to each other: older Trusted Advisor operations under the AWS Support API and the newer AWS Trusted Advisor API. If you are building new automation, start with the current Trusted Advisor API rather than copying an old command and assuming it represents the modern service surface.

The current Trusted Advisor API can retrieve recommendations and support organization-aware workflows in eligible setups. It requires Business Support+, Enterprise Support, or Unified Operations. Without an eligible plan, programmatic access is denied.

The older Support API still contains Trusted Advisor operations such as describing checks and results. Those operations have their own endpoint requirement: use the US East (N. Virginia) endpoint. That is why older AWS CLI examples often contain --region us-east-1 even when the affected resources live elsewhere.

aws support describe-trusted-advisor-checks \
  --language en \
  --region us-east-1

Do not confuse that Region flag with the scope of every finding. It is the endpoint requirement for those Support API operations, not a statement that Trusted Advisor only evaluates resources in Northern Virginia.

If that command returns SubscriptionRequiredException or an entitlement error on a Basic account, the CLI is not necessarily broken. The plan does not include the API. Use the console for the Basic checks or upgrade only when the paid-plan features are justified.

Trusted Advisor AccessDenied: Support plan or IAM?

There are two different “I cannot access Trusted Advisor” problems: entitlement and permission. Entitlement asks whether your Support plan includes the feature you are trying to use. Permission asks whether your IAM principal is allowed to perform the action.

The console has Trusted Advisor permissions for describing checks, summaries, check items, refresh statuses, notification preferences, exclusions, and organization features. You can build a role that is allowed to view recommendations without being allowed to refresh or change preferences.

If the console opens but the API returns a subscription-required response, check the plan first. If the plan is eligible but one user cannot view checks, inspect IAM. If nobody can use Trusted Advisor because the service was disabled at the account level, a policy on one user is not the missing piece.

Do not solve an IAM problem by attaching AdministratorAccess forever. Find the action the operational role needs and grant the least access that fits. Trusted Advisor is especially suitable for read-oriented roles because many people need to see recommendations without needing permission to reconfigure the affected services.

Trusted Advisor with AWS Organizations

One account is easy. Fifty accounts turn “remember to check Trusted Advisor” into a process problem. Organizational view lets eligible setups aggregate Trusted Advisor check results across member accounts in AWS Organizations.

After organizational view is enabled with the required trusted access, you can generate reports that summarize checks across accounts and include affected-resource information where the check has resource-level results. This is useful for platform teams that want to find the same class of issue across an organization instead of signing into accounts one by one.

Not every check appears in the same shape. Some checks do not have resource-level rows. MFA on root account is an example of a check that can appear in summary data rather than in a resource file. Some checks list only flagged resources even though the total evaluated count includes healthy resources.

This matters when somebody reads a CSV and concludes, “There is no MFA row for this account, so it must be green.” Absence from a resource table is not the same thing as a healthy result. Read the summary and the report semantics.

For larger organizations, ownership is usually harder than discovery. A central team can find two hundred recommendations quickly and then spend days discovering who is allowed to act on them. Add account owner, workload owner, severity, decision, and due date to your internal review process.

How to stop ignoring Trusted Advisor

The reason people ignore Trusted Advisor is rarely that the checks are useless. It is that “open another dashboard” is not an operational habit.

Start with the built-in weekly recommendation email. Trusted Advisor notification preferences let you choose who receives the weekly check summary and the language. For a small account where one or two people own AWS, that simple reminder can be enough.

For an eligible paid plan, EventBridge-based monitoring and API-driven workflows can move recommendations into systems your team already watches. The useful automation is not “auto-delete everything red.” It is “create visibility, assign ownership, and escalate genuinely urgent findings.”

  1. Review new red security findings as part of normal security operations.
  2. Review quota warnings before launches and migrations.
  3. Review cost findings monthly with resource owners.
  4. Review exclusions quarterly so temporary exceptions do not become permanent by accident.
  5. Record dismissed recommendations and why.

Jake puts the weekly email next to supplier invoice reminders. That is not sophisticated cloud governance. It is better: it is a habit he will actually keep.

Trusted Advisor vs Compute Optimizer, Security Hub, and Well-Architected

Trusted Advisor is often mistaken for a replacement for other advisory tools. It is better understood as a broad recommendation surface that can also present findings or signals from specialized systems.

ServiceBest mental modelWhy use it with Trusted Advisor
Trusted AdvisorBroad best-practice recommendation dashboardCentral triage across categories
Compute OptimizerSizing and resource-efficiency analysisDeeper analysis behind selected performance and cost recommendations
Security Hub CSPMSecurity posture management and controlsSecurity controls can surface in Trusted Advisor, while Security Hub remains the security workflow source
Well-Architected ToolStructured workload review against architecture pillarsHigh-risk issue summaries can add workload context
Service QuotasQuota viewing and increase requestsTrusted Advisor flags quota risk; Service Quotas handles many quota actions

If you only remember one difference, remember breadth versus depth. Trusted Advisor is broad. Specialist services go deeper in their domains. A mature AWS account often uses them together.

A practical monthly Trusted Advisor review routine

A dashboard only helps if somebody owns the decision it produces. For a small environment, one short review each month can be more useful than an elaborate workflow nobody maintains. The review should answer three questions: what is newly red, what is newly yellow, and what old item is still open without an owner?

Start with Security. Do not begin with potential savings because cost findings are easier to discuss and security findings are easier to postpone. For every red security item, record the exact check, resource, account, Region, owner, and next action. If the finding is intentional, record the exception instead of pretending the color is wrong.

Move to Service Limits next. A quota warning is a planning item. Look at the next release, migration, onboarding event, or seasonal spike. If expected growth could consume the remaining headroom, start the quota-increase process before the change window. A request made early is routine; the same request made during a failed launch feels like an emergency.

Then review Fault Tolerance. Separate production from development immediately. A single point of failure can be acceptable for a disposable lab environment and reckless for a customer-facing database. Trusted Advisor cannot choose your recovery objective. The check identifies a pattern; your workload requirement decides whether that pattern is acceptable.

On plans with full Cost Optimization coverage, divide recommendations into “obvious waste,” “needs owner,” and “keep intentionally.” Obvious waste is a resource whose owner confirms it is abandoned. Needs owner means the recommendation looks plausible but business context is missing. Keep intentionally means you understand the cost and accept it for a stated reason such as standby capacity, resilience, or a scheduled event.

Finish with exclusions. Every excluded item should still make sense. People exclude a recommendation during a migration, finish the migration, and forget the exception. Months later the gray item is no longer a deliberate decision; it is just history nobody remembers.

The output does not need to be a twenty-page report. A useful record is check, resource, status, owner, decision, due date, and exception reason. The purpose is to convert colored findings into accountable work.

If Trusted Advisor “is not working,” identify the failure first

SymptomLikely class of problemFirst check
Console shows only a small check setSupport-plan entitlementConfirm whether the account is on Basic or an eligible paid plan.
Console is denied for one userIAM permissionCompare that role with a principal that can open Trusted Advisor.
API fails on BasicSupport-plan entitlementDo not keep adding IAM actions; the API requires an eligible plan.
A fixed finding stays redRefresh timingCheck whether manual refresh is available or the source refreshes automatically.
A check is missing from a reportReport semanticsCheck the summary and whether the check has resource-level rows.
Security Hub finding cannot be refreshed hereSource-owned refreshReview Security Hub CSPM and wait for the integration refresh cycle.

This table is deliberately boring because boring diagnosis prevents expensive fixes. If the problem is entitlement, changing IAM will not solve it. If the problem is IAM, paying for a higher plan does not grant a role permission. If the problem is stale source data, hammering Refresh on a check that controls its own schedule wastes time.

Another edge case is account-level disablement. Trusted Advisor can be disabled from its management preferences. When it is disabled, checks stop and attempts to use the service are denied. If your organization intentionally disabled it, understand that decision before turning it back on.

A final edge case is simply lack of applicability. A check for a service you do not use may have nothing useful to report. “Nothing shown” is not a universal health statement. It can mean no applicable resource, no flagged resource, or no resource-level row for that report format.

Why everyone ignores the free checks

The first reason is the name. “Trusted Advisor” sounds like a premium consulting product. A beginner sees it near Support features and assumes it belongs to companies with a Technical Account Manager. That assumption is enough to keep a Basic user from opening a dashboard that already contains useful checks.

The second reason is alert fatigue. AWS has many places for alarms, findings, health events, budget warnings, recommendations, and security results. Another dashboard feels like another queue. The answer is not to review every dashboard every day. Decide what Trusted Advisor is for: broad recurring triage.

The third reason is that green is boring. People open dashboards during incidents. Trusted Advisor is most useful before the incident: before you run out of quota, before a public snapshot is forgotten, before an unrestricted port becomes normal, and before an unwanted resource quietly survives another billing cycle.

The fourth reason is overlap. Someone already uses Security Hub and assumes Trusted Advisor adds nothing. Someone else uses Compute Optimizer and assumes the same. The overlap is real, but the job is different. Trusted Advisor can be the broad front door that sends you into the specialist service when deeper work is required.

The fifth reason is that the Basic set is not the flashiest set. Free users do not get the entire cost-optimization catalog, so the dashboard may not immediately promise a dramatic saving. What they do get includes checks that can prevent security and deployment pain. That is a less exciting sales story and a better operational one.

Jake ignores a dashboard that says “best practices” because customers are waiting at the counter. Ethan translates the first three findings into ordinary consequences: “This one can expose data. This one can leave a door open. This one can stop a launch when you hit a limit.” The feature did not change; the language did.

My priority order when the dashboard has too many recommendations

First, review security findings that represent unintended exposure or weak account protection. A cost recommendation can wait while you understand whether a snapshot, bucket, root account, or security group has a real security problem.

Second, review quota findings tied to near-term change. A service limit at 80 percent with no growth can be less urgent than one at 60 percent when tomorrow’s migration will double usage. The percentage is not the whole priority; the workload plan matters.

Third, review fault tolerance for customer-facing and stateful systems. Ask what happens if the flagged component fails. If the honest answer is “the whole service stops and our recovery path is uncertain,” the recommendation is not architectural decoration.

Fourth, review performance recommendations where customers or internal users already feel latency, throttling, or throughput limits. Performance work without a user-visible or capacity reason can become endless tuning.

Fifth, review cost optimization with the resource owner. The best cost fix is often deleting something genuinely abandoned. The worst is deleting something whose value only becomes obvious during an incident.

Finally, review Operational Excellence items that improve long-term maintainability. They can feel less urgent minute-to-minute and still save real time over months because they reduce the amount of special knowledge the team must carry.

This order is a default, not a universal severity matrix. During a security event, security remains first by a wide margin. During a capacity incident, quota or performance can become the immediate priority. Context is the part the recommendation engine cannot own for you.

When Trusted Advisor looks wrong or nothing updates

Start by separating four problems: stale data, missing permissions, missing entitlement, and misunderstanding the check criteria.

For stale data, note the check name, last refresh time, whether manual refresh is offered, and whether the check is sourced from a service such as Security Hub that controls the refresh schedule.

For permissions, capture the IAM principal, the denied action, and whether another principal in the account can access the same page. If the entire account has Trusted Advisor disabled, the missing fix is not a policy on one user.

For entitlement, write down the Support plan. If the problem is “API denied on Basic,” there is no IAM trick that turns Basic into Business Support+. Use the console features included with the plan or change the plan for business reasons.

For a disputed finding, capture the check ID or exact check name, resource ID, account, Region, current configuration, and the alert criteria shown in the console. That package is more useful than a screenshot that only says “red.”

If you open a Support case on an eligible plan, include those facts in the first message. Do not write “Trusted Advisor broken.” Write the recommendation, resource, timestamps, what changed, and what you expected to see.

The 2026 Support-plan transition you should not miss

If you are reading old material about Developer Support, Business Support, or Enterprise On-Ramp, there is a transition underway. Developer Support and Business Support are scheduled to be discontinued on January 1, 2027 outside GovCloud, and Enterprise On-Ramp is scheduled to end then as well. The current lineup emphasizes Business Support+, Enterprise Support, and Unified Operations. Enterprise On-Ramp customers are being moved to Enterprise Support during 2026, and the Enterprise Support minimum dropped to $5,000 a month from $15,000.

That matters to a Trusted Advisor article because plan names determine what check set and API access you have. A tutorial that says “Business Support gets all checks” can be historically understandable and still be the wrong plan language for a new account decision in late 2026.

For Business Support+, the current minimum is $29 per month per account. AWS has documented transition promotions and credits, but a temporary offer should not become the reason an operational process depends on a paid feature. Make the long-term decision using the steady-state capabilities and pricing that apply to your account.

If your company is still on a legacy plan during 2026, do not panic-switch because of a blog post. Open the Support settings for your account and read the transition information tied to your plan. The operational question is whether your Trusted Advisor access and automation remain available after the transition.

AWS Trusted Advisor FAQ

What is AWS Trusted Advisor in simple words?

It is an AWS recommendation service that checks your account for known best-practice conditions and shows what deserves attention across security, quotas, resilience, performance, operations, and cost. It does not automatically fix the resources it flags.

Is AWS Trusted Advisor free?

There is a useful free core on Basic Support. Basic includes all Service Limits checks plus selected Security and Fault Tolerance checks. Full check access and programmatic API access require an eligible higher Support plan.

What Trusted Advisor checks are available with Basic Support?

Basic includes all Service Limits checks plus Amazon EBS Public Snapshots, Amazon RDS Public Snapshots, Amazon S3 Bucket Permissions, MFA on root account, Security Groups – Specific Ports Unrestricted, and AWS STS global endpoint usage across AWS Regions.

Does Trusted Advisor automatically fix problems?

No. Trusted Advisor presents recommendations and affected resources. You decide whether and how to change them. This is especially important for cost, networking, and public-access findings where an intentional design can look unusual to an automated check.

How often does AWS Trusted Advisor refresh?

Refresh behavior depends on the plan and check. Eligible paid plans receive automatic weekly refreshes generally, while some checks refresh more often. Basic users can manually refresh supported checks, including the available Security checks.

Why is Trusted Advisor still showing a problem after I fixed it?

The result may be waiting for its next refresh. Some checks can be refreshed manually; others refresh automatically and do not accept manual refresh requests. Confirm the resource configuration first, then check the recommendation’s refresh behavior.

What does red mean in AWS Trusted Advisor?

Red means Action recommended. It indicates that the check’s alert criteria were met. Review the resource before changing production; red is a priority signal, not an automatic instruction to delete or reconfigure something.

What does yellow mean in AWS Trusted Advisor?

Yellow means Investigation recommended. Treat it as an early-warning state and understand the resource before the condition becomes urgent.

Can I use the Trusted Advisor API on Basic Support?

No. The current Trusted Advisor API requires Business Support+, Enterprise Support, or Unified Operations. IAM permissions cannot unlock an API your Support plan does not include.

Why does aws support describe-trusted-advisor-checks require us-east-1?

That older command uses Trusted Advisor operations in the AWS Support API, whose Trusted Advisor operations use the US East (N. Virginia) endpoint. The endpoint Region does not mean all affected resources are in us-east-1.

Is Trusted Advisor the same as AWS Compute Optimizer?

No. Trusted Advisor is a broad recommendation surface. Compute Optimizer specializes in resource-sizing and efficiency analysis, and selected Compute Optimizer recommendations can appear in Trusted Advisor when the integration is used.

Is Trusted Advisor the same as AWS Security Hub?

No. Security Hub CSPM is a security-posture service with controls and findings. Trusted Advisor can display supported Security Hub CSPM controls, while Security Hub remains the source workflow for those findings.

Can Trusted Advisor check all AWS accounts in an Organization?

Organizational view can aggregate Trusted Advisor results across member accounts when the feature and required trusted access are enabled. Reports can include summary and resource-level detail where the check supports it.

Can I exclude a resource from Trusted Advisor?

Yes, supported checks let you exclude affected items and later include them again. Exclusion does not modify the resource or remediate the condition. Document why the exception is intentional.

Does AWS Trusted Advisor cost optimization save money automatically?

No. It can identify potential savings and affected resources, but you must validate the recommendation and make the change. Never automate deletion or resizing solely because a resource appears in a recommendation.

Is AWS Trusted Advisor worth using on a small account?

Yes. Even on Basic Support, the available security and Service Limits checks can identify issues worth reviewing. A small account is not too small for root MFA, public-permission, unrestricted-port, snapshot, and quota checks to matter.

The checklist to keep beside the console

Use Trusted Advisor as a recurring inspection rather than a once-a-year cleanup. On Basic, review the Security, Fault Tolerance, and Service Limits coverage you have. On a paid plan, add broader cost, performance, operational, API, and organization workflows where they make operational sense.

When you see red, identify the account, Region, resource, check criteria, and owner. When you see yellow, investigate before it becomes urgent. When you exclude an item, write down why. When a result stays stale, learn its refresh model before reversing a good fix. When an old tutorial tells you there are “only four free checks,” treat the tutorial as history, not as your current console.

If you have ignored this page for months, you do not need a cloud-governance project to recover. Open it once, clear the security items you understand, inspect your quotas, and make the weekly summary somebody’s responsibility. That small habit is enough to turn Trusted Advisor from another menu item into something useful.

If you find a check name, Support-plan entitlement, or refresh rule that has changed since this was written, I would rather correct the post than leave somebody troubleshooting an old product. And if your account has quietly collected red dots while everyone assumed somebody else owned them, start with one finding and one owner; you do not need to fix the whole cloud before lunch.

 If you keep one line from this page

Trusted Advisor is an inspection list, not an autopilot: use the free checks you already have, then pay for broader access only when you can name the operational reason.

A red recommendation deserves an owner, not a reflex.

Revision note. Written October 7, 2026. If this page has sat unopened in your console for months, that is normal, and one owned red item is a fine place to start.

Related