AWSHow-To & HardeningRetrospectives

S3 Object Ownership and ACL Cleanup Checklist

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from April 2023, written in 2026 with the benefit of hindsight.

Use this checklist to clean up legacy S3 ACLs and ownership settings.

Discovery

  • All buckets listed with Object Ownership setting.
  • Buckets with ACLs enabled identified.
  • Bucket ACLs with grants to AllUsers, AuthenticatedUsers or other accounts flagged.
  • Object-level ACL usage sampled for buckets that receive uploads from other accounts.

Analysis

  • For each ACL grant, business purpose identified.
  • Applications uploading objects with ACLs identified.
  • Log delivery configurations reviewed.

Migration

  • Equivalent bucket policies created for legitimate cross-account access.
  • KMS key policies updated if objects are encrypted with SSE-KMS.
  • Applications updated to stop sending non-default ACLs.
  • Object Ownership switched to Bucket owner enforced.
  • Functional tests passed.

Prevention

  • Account-level Block Public Access enabled.
  • Security Hub S3.12 and related controls enabled.
  • Infrastructure-as-code templates default to Bucket owner enforced.

Ongoing

  • New exceptions require security approval.
  • Quarterly review of buckets not compliant with S3.12.
s3 acl cleanup checklistS3 ACLs disabled by default2023

More on this story