How to Enforce S3 Block Public Access at the AWS Organization Level
Retrospective: this article looks back at events from November 2018, written in 2026 with the benefit of hindsight.
Account-level S3 Block Public Access protects every bucket in an account. With AWS Organizations, you can apply it everywhere and prevent anyone from switching it off.
Step 1: Inventory public buckets first
Before enforcing, find buckets that are intentionally public (websites, public downloads). Use IAM Access Analyzer and the S3 console's access indicators. Plan to move those to CloudFront with Origin Access Control.
Step 2: Enable account-level Block Public Access
For each account:
aws s3control put-public-access-block --account-id <ACCOUNT_ID> \
--public-access-block-configuration BlockPublicAcls=true,IgnorePublicAcls=true,BlockPublicPolicy=true,RestrictPublicBuckets=true
Automate across accounts with CloudFormation StackSets, AWS Control Tower controls, or your infrastructure-as-code tool.
Step 3: Prevent changes with an SCP
Attach a Service Control Policy to your organization root or workload OUs:
{
"Version": "2012-10-17",
"Statement": [{
"Sid": "DenyS3PublicAccessBlockChanges",
"Effect": "Deny",
"Action": ["s3:PutAccountPublicAccessBlock"],
"Resource": "*"
}]
}
Exempt a break-glass role if you need a controlled way to change settings.
Step 4: Monitor
Enable the AWS Config rule s3-account-level-public-access-blocks-periodic and send results to Security Hub.
Step 5: Handle exceptions deliberately
If an account truly needs public buckets, isolate it in a dedicated account and OU with its own review process.
- S3 Block Public Access Launches (Nov 2018): The Feature That Should Have Existed Day One Platform Changes
- S3 Public Access Audit Checklist How-To & Hardening
- CIO Brief: One Setting That Prevents the Most Common Cloud Breach CIO Briefings