AWSHow-To & HardeningRetrospectives

How to Enforce S3 Block Public Access at the AWS Organization Level

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2018, written in 2026 with the benefit of hindsight.

Account-level S3 Block Public Access protects every bucket in an account. With AWS Organizations, you can apply it everywhere and prevent anyone from switching it off.

Step 1: Inventory public buckets first

Before enforcing, find buckets that are intentionally public (websites, public downloads). Use IAM Access Analyzer and the S3 console's access indicators. Plan to move those to CloudFront with Origin Access Control.

Step 2: Enable account-level Block Public Access

For each account:

aws s3control put-public-access-block --account-id <ACCOUNT_ID> \
  --public-access-block-configuration BlockPublicAcls=true,IgnorePublicAcls=true,BlockPublicPolicy=true,RestrictPublicBuckets=true

Automate across accounts with CloudFormation StackSets, AWS Control Tower controls, or your infrastructure-as-code tool.

Step 3: Prevent changes with an SCP

Attach a Service Control Policy to your organization root or workload OUs:

{
  "Version": "2012-10-17",
  "Statement": [{
    "Sid": "DenyS3PublicAccessBlockChanges",
    "Effect": "Deny",
    "Action": ["s3:PutAccountPublicAccessBlock"],
    "Resource": "*"
  }]
}

Exempt a break-glass role if you need a controlled way to change settings.

Step 4: Monitor

Enable the AWS Config rule s3-account-level-public-access-blocks-periodic and send results to Security Hub.

Step 5: Handle exceptions deliberately

If an account truly needs public buckets, isolate it in a dedicated account and OU with its own review process.

s3 block public access organizationS3 Block Public Access2018

More on this story