IMDSv2 Enforcement Checklist With SCPs and Launch Templates
Retrospective: this article looks back at events from November 2019, written in 2026 with the benefit of hindsight.
Use this checklist to make IMDSv2 mandatory across your AWS organization and keep it that way.
Discovery
- Security Hub control EC2.8 (EC2 instances should use IMDSv2) is enabled in all accounts.
- A report lists instances with
HttpTokens=optionalby account and owner. - CloudWatch
MetadataNoTokenmetrics reviewed for each instance.
Remediation
- SDKs, CLI and agents updated on instances still making IMDSv1 calls.
- Existing instances updated to
HttpTokens=requiredwith hop limit 1 (or 2 for container hosts that need it). - Launch templates and Auto Scaling groups updated.
- Golden AMIs built with IMDSv2 required (
imds-support v2.0).
Defaults
- EC2 account-level instance metadata defaults set to require IMDSv2 in every region.
Preventive controls
- SCP or IAM policy denies
ec2:RunInstancesunlessec2:MetadataHttpTokensequalsrequired. - SCP denies
ec2:ModifyInstanceMetadataOptionsthat would re-enable IMDSv1, except for an approved role. - Infrastructure-as-code modules default to IMDSv2.
Complementary controls
- Instance roles reviewed for least privilege.
- GuardDuty enabled to detect instance credential exfiltration.
Ongoing
- Monthly check of EC2.8 compliance.
- New AMIs and third-party agents tested for IMDSv2 compatibility before approval.
- AWS Launches IMDSv2 (Nov 2019): Closing the Capital One Attack Path Platform Changes
- How to Migrate an EC2 Fleet to IMDSv2 Without Breaking Applications How-To & Hardening
- CIO Brief: How One AWS Setting Answers the Capital One Breach CIO Briefings