Description
An IAM user can have up to two access keys, and both may be needed briefly during rotation. Keeping unused keys indefinitely makes usage tracking and revocation harder.
Potential impact
Unneeded active keys leave additional credentials that can be misused if exposed. Unclear ownership or usage can also delay incident response.
Remediation
Prefer roles and temporary credentials. If long-lived keys are necessary, identify their consumers, switch to the new key and deactivate the old one. Verify normal operation before deleting the old key.
Examples
The examples compare issuing two keys to one user with retaining a single key. Console login settings are not included.
Before
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template
Resources:
myuser:
Type: AWS::IAM::User
Properties:
Path: "/"
firstKey:
Type: AWS::IAM::AccessKey
Properties:
UserName: !Ref myuser
secondKey:
Type: AWS::IAM::AccessKey
Properties:
UserName: !Ref myuser
Two keys are created. Check whether this is a temporary rotation overlap or an unnecessary retained key.
After
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template
Resources:
myuser:
Type: AWS::IAM::User
Properties:
Path: "/"
firstKey:
Type: AWS::IAM::AccessKey
Properties:
UserName:
Ref: myuser
One key is retained. Even a single key needs protection and usage tracking.