How to Find, Disable and Replace Long-Lived AWS Access Keys
Thousands of exposed AWS access keys remain active years after leaking. Here is how to find, disable and replace long-lived keys in your accounts.
Step 1: Find every access key
- Credential report per account (
aws iam generate-credential-reportandget-credential-report) shows each user's keys, creation date and last use. - IAM Access Analyzer unused access findings across the organization show unused keys.
- Security Hub controls flag root access keys and keys older than 90 days.
- Check the root user in every account; with AWS Organizations, use centralized root access management to see and remove root credentials in member accounts.
Step 2: Prioritize
- Root access keys — delete immediately.
- Keys with admin or broad permissions.
- Keys not used in 90 days — deactivate.
- Keys older than 90 days in use — schedule replacement.
Step 3: Deactivate before deleting
Set unused keys to Inactive, monitor for errors for two weeks, then delete. For keys in use, plan replacement first.
Step 4: Replace with roles
- People: IAM Identity Center.
- Workloads on AWS: IAM roles.
- CI/CD: OIDC federation.
- Outside AWS: IAM Roles Anywhere or federation.
Step 5: Check for exposure
Search code repositories (current and history), wikis, tickets and public sources for your key IDs (AKIA...). Rotate any found.
Step 6: Respond to AWS notifications
AWS may notify you and attach a quarantine policy to exposed keys. Route these notifications to security on-call, and treat them as incidents.
Step 7: Prevent new keys
SCP or permission boundaries restricting iam:CreateAccessKey, plus alerts on any key creation.
Verify
Monthly count of active IAM user keys and root keys across the organization. Targets: zero root keys; near-zero user keys in production.
Sources
- Thousands of Exposed AWS Access Keys Are Still Active (2026): Including Hundreds of Root Keys Incident Teardowns
- Detecting Leaked AWS Root Keys: CloudTrail, GuardDuty and Athena Queries Detection & Response
- CIO Brief: Old Leaked Keys Are Still Open Doors CIO Briefings