Description
AWS account root access keys carry highly privileged access and should not be created or retained. Prefer temporary credentials from least-privilege roles for automation.
For CloudFormation AWS::IAM::AccessKey, UserName identifies an IAM user. An IAM user named Root is not the account root user, and its name does not establish its permissions. Check the actual owner, key status and attached policies.
Potential impact
- Exposure of a real root key can cause broad damage to account data, resources and security settings.
- A regular IAM user key can also be abused for the user’s permitted operations while it remains active.
Remediation
- Identify automation that depends on long-term keys and move it to temporary credentials from least-privilege roles.
- Check consumers of unnecessary keys, deactivate the keys, verify normal operation and delete them. Revoke exposed root keys promptly and investigate account activity.
- Protect the root account and maintain MFA, but do not assume MFA automatically invalidates a leaked long-term access key.
Examples
These examples concern an existing IAM user named Root. They do not create or manage account root keys. Confirm the actual user and key before applying changes.
Before
Resources:
CFNKeys:
Type: AWS::IAM::AccessKey
Properties:
UserName: Root
A new key defaults to active when Status is omitted. The IAM user’s policies determine its permissions, even when its name is Root.
After
Resources:
CFNKeys:
Type: AWS::IAM::AccessKey
Properties:
UserName: Root
Status: Inactive
The same IAM user key is made inactive. Unlike merely changing the user name, this stops API use of that key. Delete unnecessary keys after migrating their consumers.