Review the number of IAM user access keys

Remove unnecessary IAM user access keys and retire old keys after rotation.

Description

An IAM user can have up to two access keys, and both may be needed briefly during rotation. Keeping unused keys indefinitely makes usage tracking and revocation harder.

Potential impact

Unneeded active keys leave additional credentials that can be misused if exposed. Unclear ownership or usage can also delay incident response.

Remediation

Prefer roles and temporary credentials. If long-lived keys are necessary, identify their consumers, switch to the new key and deactivate the old one. Verify normal operation before deleting the old key.

Examples

The examples compare issuing two keys to one user with retaining a single key. Console login settings are not included.

Before

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template
Resources:
  myuser:
    Type: AWS::IAM::User
    Properties:
      Path: "/"
  firstKey:
    Type: AWS::IAM::AccessKey
    Properties:
      UserName: !Ref myuser
  secondKey:
    Type: AWS::IAM::AccessKey
    Properties:
      UserName: !Ref myuser

Two keys are created. Check whether this is a temporary rotation overlap or an unnecessary retained key.

After

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template
Resources:
  myuser:
    Type: AWS::IAM::User
    Properties:
      Path: "/"
  firstKey:
    Type: AWS::IAM::AccessKey
    Properties:
      UserName:
        Ref: myuser

One key is retained. Even a single key needs protection and usage tracking.

References