AWSHow-To & HardeningRetrospectives

IMDSv2 Enforcement Checklist With SCPs and Launch Templates

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2019, written in 2026 with the benefit of hindsight.

Use this checklist to make IMDSv2 mandatory across your AWS organization and keep it that way.

Discovery

  • Security Hub control EC2.8 (EC2 instances should use IMDSv2) is enabled in all accounts.
  • A report lists instances with HttpTokens=optional by account and owner.
  • CloudWatch MetadataNoToken metrics reviewed for each instance.

Remediation

  • SDKs, CLI and agents updated on instances still making IMDSv1 calls.
  • Existing instances updated to HttpTokens=required with hop limit 1 (or 2 for container hosts that need it).
  • Launch templates and Auto Scaling groups updated.
  • Golden AMIs built with IMDSv2 required (imds-support v2.0).

Defaults

  • EC2 account-level instance metadata defaults set to require IMDSv2 in every region.

Preventive controls

  • SCP or IAM policy denies ec2:RunInstances unless ec2:MetadataHttpTokens equals required.
  • SCP denies ec2:ModifyInstanceMetadataOptions that would re-enable IMDSv1, except for an approved role.
  • Infrastructure-as-code modules default to IMDSv2.

Complementary controls

  • Instance roles reviewed for least privilege.
  • GuardDuty enabled to detect instance credential exfiltration.

Ongoing

  • Monthly check of EC2.8 compliance.
  • New AMIs and third-party agents tested for IMDSv2 compatibility before approval.
imdsv2 enforcement scp checklistIMDSv22019

More on this story