How to Replace Long-Lived AWS Access Keys With IAM Roles and Identity Center
Retrospective: this article looks back at events from August 2019, written in 2026 with the benefit of hindsight.
Long-lived IAM user access keys are one of the most common causes of AWS breaches. IAM roles and IAM Identity Center provide short-lived credentials instead. Here is how to migrate.
Step 1: Inventory access keys
Generate the IAM credential report in each account:
aws iam generate-credential-report
aws iam get-credential-report --query Content --output text | base64 --decode > report.csv
List every user with an active access key, its age and when it was last used. Unused keys are easy wins: deactivate them first.
Step 2: Classify each key's use
- People using the CLI or SDKs from laptops.
- Applications running on AWS (EC2, ECS, Lambda, EKS).
- CI/CD pipelines.
- Applications outside AWS (on-premises servers, other clouds, SaaS integrations).
Step 3: Replace by category
- People: IAM Identity Center with your identity provider;
aws sso loginprovides temporary credentials. - Workloads on AWS: instance profiles, ECS task roles, Lambda execution roles, EKS Pod Identity.
- CI/CD: OIDC federation (GitHub Actions, GitLab, Azure DevOps) to assume a role.
- Outside AWS: IAM Roles Anywhere with X.509 certificates; or, for Azure workloads, federation with Entra ID managed identities.
- SaaS integrations: cross-account roles with an external ID where the vendor supports it.
Step 4: Remove the keys
Deactivate, monitor for errors for two weeks, then delete.
Step 5: Prevent new keys
Use an SCP to deny iam:CreateAccessKey except for an approved exceptions role, and alert on any creation.
Verify
Track the number of active IAM user access keys per account; the target in production accounts is zero.
- Imperva's Cloud WAF Breach (Aug 2019): A Stolen AWS API Key From an Internal Instance Incident Teardowns
- Detecting Stolen AWS API Keys: CloudTrail, GuardDuty and Athena Queries Detection & Response
- CIO Brief: When Your Security Vendor Loses Its Cloud Keys CIO Briefings