The 30-minute AWS IAM cleanup checklist
Stale keys, root usage, and admin sprawl are the most common findings in small-team AWS accounts. Here’s how to find them fast — and what to fix first.
Small-team AWS accounts rarely get breached through something exotic. It’s usually an old access key, an over-permissioned user, or a root account nobody locked down. The good news: most of it can be found in half an hour.
1. Lock down root (5 minutes)
- Confirm MFA is enabled on the root user — ideally a hardware key.
- Check there are no root access keys. There’s almost never a reason for them.
- Make sure the root email is a shared, monitored address — not a former employee’s inbox.
2. Pull the credential report (5 minutes)
In IAM, generate the credential report. It’s a CSV of every user, their MFA status, password age, and when each access key was last used.
aws iam generate-credential-report
aws iam get-credential-report --query Content --output text | base64 -d > creds.csv
Sort by access_key_1_last_used_date. Anything unused for 90+ days is a candidate for deactivation.
3. Find the admins (10 minutes)
List who has AdministratorAccess or *:* policies — attached directly, through groups, or through roles. In most small accounts, that list is longer than anyone expects.
Your goal: a small number of humans with admin, all via IAM Identity Center (SSO) with MFA, and no long-lived keys.
4. Fix in this order
- Deactivate (don’t delete yet) stale access keys. Wait a week. Then delete.
- Enforce MFA for every remaining console user.
- Move humans to IAM Identity Center and retire IAM users where possible.
- Replace
AdministratorAccesswith scoped roles for day-to-day work. - Turn on IAM Access Analyzer to flag resources shared outside the account.
Keep it clean
Cleanup is a one-time effort. Staying clean is a habit. A monthly review of the credential report and admin list catches drift before it becomes a finding.
That monthly habit is the core of cloud hygiene.