AWSPlatform ChangesRetrospectives

S3 Block Public Access and ACLs Disabled by Default for New Buckets (Apr 2023)

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from April 2023, written in 2026 with the benefit of hindsight.

In April 2023, AWS changed the default settings for all new S3 buckets: S3 Block Public Access is enabled, and access control lists (ACLs) are disabled (Object Ownership set to "Bucket owner enforced").

What changed

  • New buckets can't be made public through policies or ACLs unless someone first turns off Block Public Access.
  • ACLs no longer affect access to new buckets; access is controlled only by policies.
  • Applications that relied on ACLs (for example, granting access to objects uploaded by other accounts) needed updates.

Why it mattered

For years, AWS had recommended disabling ACLs and blocking public access, but defaults favored backward compatibility. Changing defaults meant every new bucket started secure — removing one of the most common causes of cloud data leaks from new deployments.

What it didn't change

Existing buckets kept their settings. Accounts created years earlier, and buckets created before April 2023, could still have ACLs enabled and public access allowed. Organizations had to address those deliberately.

In hindsight

The 2023 defaults closed the loop on the S3 leak era that began in 2017. The remaining risk lies in older resources and in people deliberately turning protections off — which is why account-level Block Public Access, SCPs and monitoring remain important.

s3 acl disabled by defaultS3 ACLs disabled by default2023

More on this story