Description
RestrictPublicBuckets limits access to an S3 bucket with a public policy to AWS service principals and authorized users in the bucket owner’s account. Without this protection, external access granted by the public policy may be possible. Other controls, including account-level blocks, still apply.
The setting does not delete the public policy. It can also block a separate grant to a specific external account when the policy is classified as public, so check required cross-account integrations.
Potential impact
- A public policy granting object reads can expose data to unintended users.
- Public write or delete permissions can also allow data changes or loss.
Remediation
- For private buckets, set
PublicAccessBlockConfiguration.RestrictPublicBuckets: true. - Remove unnecessary public policy statements and name only required accounts and roles. Verify required service and cross-account access after the change.
- Review
BlockPublicPolicyand the ACL blocking controls too. Rejecting new public policies does not remove access granted by an existing public policy.
Examples
These examples compare Block Public Access settings on the same bucket.
Before
Resources:
Bucket13:
Type: AWS::S3::Bucket
Properties:
PublicAccessBlockConfiguration:
BlockPublicAcls: false
BlockPublicPolicy: true
IgnorePublicAcls: false
RestrictPublicBuckets: false
RestrictPublicBuckets does not restrict access granted by an existing public policy. Account-level blocks still apply, and this setting alone does not establish that a public policy exists.
After
Resources:
Bucket13:
Type: AWS::S3::Bucket
Properties:
PublicAccessBlockConfiguration:
BlockPublicAcls: true
BlockPublicPolicy: true
IgnorePublicAcls: true
RestrictPublicBuckets: true
Access is restricted when the bucket has a public policy, and the other public-access blocks are enabled. To preserve required external-account access, remove public grants and explicitly configure that account’s permissions.