AWSHow-To & HardeningRetrospectives

How to Replace Long-Lived AWS Access Keys With IAM Roles and Identity Center

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from August 2019, written in 2026 with the benefit of hindsight.

Long-lived IAM user access keys are one of the most common causes of AWS breaches. IAM roles and IAM Identity Center provide short-lived credentials instead. Here is how to migrate.

Step 1: Inventory access keys

Generate the IAM credential report in each account:

aws iam generate-credential-report
aws iam get-credential-report --query Content --output text | base64 --decode > report.csv

List every user with an active access key, its age and when it was last used. Unused keys are easy wins: deactivate them first.

Step 2: Classify each key's use

  • People using the CLI or SDKs from laptops.
  • Applications running on AWS (EC2, ECS, Lambda, EKS).
  • CI/CD pipelines.
  • Applications outside AWS (on-premises servers, other clouds, SaaS integrations).

Step 3: Replace by category

  • People: IAM Identity Center with your identity provider; aws sso login provides temporary credentials.
  • Workloads on AWS: instance profiles, ECS task roles, Lambda execution roles, EKS Pod Identity.
  • CI/CD: OIDC federation (GitHub Actions, GitLab, Azure DevOps) to assume a role.
  • Outside AWS: IAM Roles Anywhere with X.509 certificates; or, for Azure workloads, federation with Entra ID managed identities.
  • SaaS integrations: cross-account roles with an external ID where the vendor supports it.

Step 4: Remove the keys

Deactivate, monitor for errors for two weeks, then delete.

Step 5: Prevent new keys

Use an SCP to deny iam:CreateAccessKey except for an approved exceptions role, and alert on any creation.

Verify

Track the number of active IAM user access keys per account; the target in production accounts is zero.

replace aws access keys with rolesImperva AWS key2019

More on this story