Review the access key age threshold

Manage both the access key age threshold and the actual rotation process.

Description

A leaked long-lived access key can be misused until it is revoked. AWS Config ACCESS_KEYS_ROTATED evaluates the age of active IAM user keys; it does not rotate or deactivate them automatically.

Potential impact

Old or unused keys that remain valid leave unnecessary credentials in place and can complicate incident response.

Remediation

Prefer IAM roles and temporary credentials. If your organization applies a 90-day limit to long-lived keys, set maxAccessKeyAge to 90 or less and operate a process to rotate keys, update consumers, and deactivate and delete old keys.

Examples

The examples change the evaluation threshold from 100 days to 90 days. AWS Config setup is separate, and this rule does not evaluate root user keys.

Before

yaml
Resources:
  ConfigRule:
    Type: AWS::Config::ConfigRule
    Properties:
      ConfigRuleName: access-keys-rotated
      InputParameters:
        maxAccessKeyAge: 100
      Source:
        Owner: AWS
        SourceIdentifier: ACCESS_KEYS_ROTATED
      MaximumExecutionFrequency: TwentyFour_Hours

Key age is evaluated against a 100-day threshold.

After

yaml
Resources:
  ConfigRule:
    Type: AWS::Config::ConfigRule
    Properties:
      ConfigRuleName: access-keys-rotated
      InputParameters:
        maxAccessKeyAge: 90
      Source:
        Owner: AWS
        SourceIdentifier: ACCESS_KEYS_ROTATED
      MaximumExecutionFrequency: TwentyFour_Hours

The threshold is 90 days. This change alone does not expire or rotate keys.

References