Review S3 public-policy blocking

Align S3 public-policy blocking with actual public-access requirements and other access controls.

Description

S3 BlockPublicPolicy rejects requests to save a bucket policy that S3 considers public. Disabling it does not itself make data public. New buckets have Block Public Access enabled by default, and omission from a template does not establish that the deployed protection is disabled.

The most restrictive applicable bucket-level, account-level and other Block Public Access settings take precedence. Enabling BlockPublicPolicy does not remove an existing policy, so current permissions still need review.

Potential impact

If a private bucket does not reject public-policy changes, a later mistaken grant can increase the risk of external data exposure. The effective exposure depends on the policy’s actions and resources and other access controls.

Remediation

  • Explicitly enable all four Block Public Access options for private buckets.
  • Remove unnecessary public permissions from existing bucket policies and ACLs, and check account-level settings.
  • For intentional public services, review the required scope and alternative designs. Test that protection changes preserve legitimate service and required cross-account access.

Examples

The examples compare settings on the same bucket. Policies and ACLs grant permissions separately; these settings alone do not grant public object access.

Before

yaml
Resources:
  Bucket13:
    Type: AWS::S3::Bucket
    Properties:
      PublicAccessBlockConfiguration:
        BlockPublicAcls: false
        BlockPublicPolicy: false
        IgnorePublicAcls: false
        RestrictPublicBuckets: true

BlockPublicPolicy is disabled while RestrictPublicBuckets remains enabled. These controls serve different purposes, and applicable account-level protection must also be checked.

After

yaml
Resources:
  Bucket13:
    Type: AWS::S3::Bucket
    Properties:
      PublicAccessBlockConfiguration:
        BlockPublicAcls: true
        BlockPublicPolicy: true
        IgnorePublicAcls: true
        RestrictPublicBuckets: true

All four blocking options are enabled. This does not delete existing policies or ACLs, so remove unnecessary public grants and validate required access as well.

References