How to Find, Disable and Replace Long-Lived AWS Access Keys

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Thousands of exposed AWS access keys remain active years after leaking. Here is how to find, disable and replace long-lived keys in your accounts.

Step 1: Find every access key

  • Credential report per account (aws iam generate-credential-report and get-credential-report) shows each user's keys, creation date and last use.
  • IAM Access Analyzer unused access findings across the organization show unused keys.
  • Security Hub controls flag root access keys and keys older than 90 days.
  • Check the root user in every account; with AWS Organizations, use centralized root access management to see and remove root credentials in member accounts.

Step 2: Prioritize

  1. Root access keys — delete immediately.
  2. Keys with admin or broad permissions.
  3. Keys not used in 90 days — deactivate.
  4. Keys older than 90 days in use — schedule replacement.

Step 3: Deactivate before deleting

Set unused keys to Inactive, monitor for errors for two weeks, then delete. For keys in use, plan replacement first.

Step 4: Replace with roles

  • People: IAM Identity Center.
  • Workloads on AWS: IAM roles.
  • CI/CD: OIDC federation.
  • Outside AWS: IAM Roles Anywhere or federation.

Step 5: Check for exposure

Search code repositories (current and history), wikis, tickets and public sources for your key IDs (AKIA...). Rotate any found.

Step 6: Respond to AWS notifications

AWS may notify you and attach a quarantine policy to exposed keys. Route these notifications to security on-call, and treat them as incidents.

Step 7: Prevent new keys

SCP or permission boundaries restricting iam:CreateAccessKey, plus alerts on any key creation.

Verify

Monthly count of active IAM user keys and root keys across the organization. Targets: zero root keys; near-zero user keys in production.

Sources

  1. Source
disable aws access keys9,300 exposed AWS keys still active2026

More on this story