S3 Object Ownership and ACL Cleanup Checklist
Retrospective: this article looks back at events from April 2023, written in 2026 with the benefit of hindsight.
Use this checklist to clean up legacy S3 ACLs and ownership settings.
Discovery
- All buckets listed with Object Ownership setting.
- Buckets with ACLs enabled identified.
- Bucket ACLs with grants to
AllUsers,AuthenticatedUsersor other accounts flagged. - Object-level ACL usage sampled for buckets that receive uploads from other accounts.
Analysis
- For each ACL grant, business purpose identified.
- Applications uploading objects with ACLs identified.
- Log delivery configurations reviewed.
Migration
- Equivalent bucket policies created for legitimate cross-account access.
- KMS key policies updated if objects are encrypted with SSE-KMS.
- Applications updated to stop sending non-default ACLs.
- Object Ownership switched to Bucket owner enforced.
- Functional tests passed.
Prevention
- Account-level Block Public Access enabled.
- Security Hub S3.12 and related controls enabled.
- Infrastructure-as-code templates default to Bucket owner enforced.
Ongoing
- New exceptions require security approval.
- Quarterly review of buckets not compliant with S3.12.