Review access restrictions for S3 public policies

Restrict access to S3 buckets with public policies and remove unnecessary public grants.

Description

RestrictPublicBuckets limits access to an S3 bucket with a public policy to AWS service principals and authorized users in the bucket owner’s account. Without this protection, external access granted by the public policy may be possible. Other controls, including account-level blocks, still apply.

The setting does not delete the public policy. It can also block a separate grant to a specific external account when the policy is classified as public, so check required cross-account integrations.

Potential impact

  • A public policy granting object reads can expose data to unintended users.
  • Public write or delete permissions can also allow data changes or loss.

Remediation

  • For private buckets, set PublicAccessBlockConfiguration.RestrictPublicBuckets: true.
  • Remove unnecessary public policy statements and name only required accounts and roles. Verify required service and cross-account access after the change.
  • Review BlockPublicPolicy and the ACL blocking controls too. Rejecting new public policies does not remove access granted by an existing public policy.

Examples

These examples compare Block Public Access settings on the same bucket.

Before

yaml
Resources:
  Bucket13:
    Type: AWS::S3::Bucket
    Properties:
      PublicAccessBlockConfiguration:
        BlockPublicAcls: false
        BlockPublicPolicy: true
        IgnorePublicAcls: false
        RestrictPublicBuckets: false

RestrictPublicBuckets does not restrict access granted by an existing public policy. Account-level blocks still apply, and this setting alone does not establish that a public policy exists.

After

yaml
Resources:
  Bucket13:
    Type: AWS::S3::Bucket
    Properties:
      PublicAccessBlockConfiguration:
        BlockPublicAcls: true
        BlockPublicPolicy: true
        IgnorePublicAcls: true
        RestrictPublicBuckets: true

Access is restricted when the bucket has a public policy, and the other public-access blocks are enabled. To preserve required external-account access, remove public grants and explicitly configure that account’s permissions.

References